nerdexam
CompTIA

CS0-003 · Question #589

A security analyst reviews the following output: Which of the following malicious activities is occurring?

The correct answer is D. ARP scanning. The repeated ARP requests from the same source MAC address for a sequence of IP addresses (e.g., 172.20.0.1 to 172.20.0.12) indicate ARP scanning. This is typically used to map out live hosts on a network by identifying which IPs respond to ARP requests.

Submitted by fernanda_arg· Mar 6, 2026Security Operations

Question

A security analyst reviews the following output:

Which of the following malicious activities is occurring?

Exhibit

CS0-003 question #589 exhibit

Options

  • AARP poisoning
  • BMAC flooding
  • CARP spoofing
  • DARP scanning

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    17% (5)
  • D
    72% (21)

Explanation

The repeated ARP requests from the same source MAC address for a sequence of IP addresses (e.g., 172.20.0.1 to 172.20.0.12) indicate ARP scanning. This is typically used to map out live hosts on a network by identifying which IPs respond to ARP requests.

Topics

#ARP scanning#network reconnaissance#packet analysis

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice