Case B766DA · Network · L2 Practitioner
ARP Spoofing
Practise as: Explain it · Interview
Interview questionHow does ARP spoofing enable a man-in-the-middle attack on a LAN, and how do you stop it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- ARP maps IPv4 to MAC with no authentication; hosts accept unsolicited (gratuitous) replies and update caches
- Attacker poisons victim and gateway caches with its own MAC, then forwards traffic to sit in the middle
- Enables sniffing, session hijacking, and SSL stripping of non-HSTS sites; tools include arpspoof, Bettercap
- Defense: Dynamic ARP Inspection validating against DHCP snooping bindings on managed switches
- Detect via duplicate MAC for gateway IP, arpwatch alerts; encryption (TLS, SMB signing) limits the impact
If the interviewer pushes back
- What is the IPv6 equivalent of this attack, and which switch features defend against it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.