SY0-701 · Question #691
While a school district is performing state testing, a security analyst notices all internet services are unavailable. The analyst discovers that ARP poisoning is occurring on the network and then…
The correct answer is C. Insider threat. ARP poisoning is a Layer 2, local-network attack - the attacker must be physically or logically on the same network segment to send spoofed ARP replies, which points directly to an insider threat (C). The deliberate timing during state testing also signals someone with…
Question
While a school district is performing state testing, a security analyst notices all internet services are unavailable. The analyst discovers that ARP poisoning is occurring on the network and then terminates access for the host. Which of the following is most likely responsible for this malicious activity?
Options
- AUnskilled attacker
- BShadow IT
- CInsider threat
- DNation-state
How the community answered
(24 responses)- A8% (2)
- B4% (1)
- C83% (20)
- D4% (1)
Explanation
ARP poisoning is a Layer 2, local-network attack - the attacker must be physically or logically on the same network segment to send spoofed ARP replies, which points directly to an insider threat (C). The deliberate timing during state testing also signals someone with knowledge of school operations, reinforcing insider motive and opportunity.
Why the distractors are wrong:
- A (Unskilled attacker): ARP poisoning requires technical know-how and - critically - local network access; an unskilled external attacker couldn't execute this.
- B (Shadow IT): Shadow IT describes unauthorized but unintentionally harmful devices/software (e.g., a personal hotspot); it implies no malicious intent, unlike a deliberate attack.
- D (Nation-state): Nation-state actors use sophisticated, stealthy, long-term campaigns (APTs) against high-value targets - not disruptive LAN-layer attacks on a school district.
Memory tip: Think "ARP = Adjacent = Insider." Any attack that requires being on the same local network (ARP, DHCP starvation, MAC flooding) implies the attacker is adjacent to the network - a hallmark of an insider threat scenario on the exam.
Topics
Community Discussion
No community discussion yet for this question.