nerdexam
CompTIA

PT0-003 · Question #222

A penetration tester is performing a network security assessment. The tester wants to intercept communication between two users and then view and potentially modify transmitted data. Which of the…

The correct answer is B. ARP poisoning. An on-path attack (previously known as MITM ?Man-in-the-Middle) allows an attacker to intercept and modify communication between two parties. Attackers send fake ARP replies to associate their MAC address with the IP address of a legitimate device (e.g., gateway). This forces…

Submitted by yaw92· Mar 6, 2026Attacks and Exploits

Question

A penetration tester is performing a network security assessment. The tester wants to intercept communication between two users and then view and potentially modify transmitted data. Which of the following types of on-path attacks would be best to allow the penetration tester to achieve this result?

Options

  • ADNS spoofing
  • BARP poisoning
  • CVLAN hopping
  • DSYN flooding

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    89% (39)
  • C
    2% (1)
  • D
    2% (1)

Explanation

An on-path attack (previously known as MITM ?Man-in-the-Middle) allows an attacker to intercept and modify communication between two parties. Attackers send fake ARP replies to associate their MAC address with the IP address of a legitimate device (e.g., gateway). This forces traffic to flow through the attacker's system, enabling packet capture and manipulation. Tools like Ettercap, Bettercap, and ARP spoofing scripts are commonly used.

Topics

#ARP poisoning#on-path attack#MITM#network interception

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice