HPE7-A02 · Question #70
Refer to the Exhibit. These packets have been captured from VLAN 10. which supports clients that receive their IP addresses with DHCP. What can you interpret from the packets that you see here?…
The correct answer is A. Someone is possibly implementing a MAC spoofing attack to gain unauthorized access. Option A is correct because the captured packets likely show the same MAC address appearing on two different devices (or the same MAC associated with conflicting DHCP leases). In a MAC spoofing attack, an attacker copies a legitimate client's MAC address to impersonate it…
Question
Refer to the Exhibit. These packets have been captured from VLAN 10. which supports clients that receive their IP addresses with DHCP. What can you interpret from the packets that you see here? These packets have been captured from VLAN 10, which supports clients that receive their IP addresses with DHCP. What can you interpret from the packets that you see here?
Exhibit
Options
- ASomeone is possibly implementing a MAC spoofing attack to gain unauthorized access.
- BThe mirroring session that captured the packets was likely misconfigured and captured duplicate
- CAn admin has likely misconfigured two clients to use the same DHCP settings.
- DSomeone is possibly implementing an ARP poisoning and MITM attack.
How the community answered
(30 responses)- A77% (23)
- B13% (4)
- C3% (1)
- D7% (2)
Explanation
Option A is correct because the captured packets likely show the same MAC address appearing on two different devices (or the same MAC associated with conflicting DHCP leases). In a MAC spoofing attack, an attacker copies a legitimate client's MAC address to impersonate it - bypassing MAC-based access controls and potentially stealing an authorized DHCP lease to gain unauthorized network access on VLAN 10.
Why the distractors are wrong:
- B is wrong because a misconfigured mirror port would produce duplicate frames of the same packet, not conflicting identity information tied to the MAC layer.
- C is wrong because two clients accidentally sharing DHCP settings would trigger a duplicate IP conflict (seen via ARP probes/announcements), not the same MAC address appearing across separate devices.
- D is wrong because ARP poisoning shows a device sending gratuitous ARP replies claiming ownership of another's IP (e.g., the gateway) - distinct from the MAC-level identity theft shown here.
Memory tip: Think "MAC = identity theft, ARP = address hijacking." If the same hardware address (MAC) appears where it shouldn't, someone stole a device's identity (spoofing). If a device is aggressively claiming someone else's IP, that's ARP poisoning. The layer of the attack tells you which is which.
Topics
Community Discussion
No community discussion yet for this question.
