Home > Glossary > CompTIA PenTest+ > ARP Poisoning

📖 What is ARP Poisoning?

ARP Poisoning is a technique used to associate an attacker's MAC address with the IP address of another host, such as the default gateway. This enables the attacker to intercept, modify, or stop traffic flowing between two devices on a local area network.

🥋 Sensei Says:

"This is the foundation of a Man-in-the-Middle (MitM) attack. For the exam, associate this specifically with Layer 2 of the OSI model."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of ARP Poisoning?

  • Gratuitous ARP involves sending unsolicited ARP responses to targets, forcing them to update their ARP cache with the attacker's MAC address.
  • Operates strictly at Layer 2 of the OSI model, manipulating the mapping between IP addresses and hardware MAC addresses on a local segment.
  • Serves as the primary mechanism for Man-in-the-Middle (MitM) attacks, allowing an attacker to sniff, modify, or drop packets between two hosts.
  • ARP Cache Poisoning targets the local memory table of a device, replacing legitimate gateway information with the attacker's own network interface details.
  • Mitigation focuses on Dynamic ARP Inspection (DAI), which uses a DHCP snooping database to validate ARP packets and block fraudulent responses.

🎯 How does ARP Poisoning appear on the PT0-002 Exam?

You may be asked to identify the attack being performed when a tester uses tools like Ettercap or Bettercap to intercept traffic between a workstation and a gateway.

A scenario might describe a local network where traffic is being redirected to a rogue host; you will need to select the correct mitigation, such as enabling DAI on the switch.

Expect questions where you must distinguish between Layer 2 attacks like ARP poisoning and Layer 3 attacks like IP spoofing based on the OSI layer mentioned.

❓ Frequently Asked Questions

How does ARP poisoning differ from DNS spoofing?

ARP poisoning operates at Layer 2 to map an IP to a wrong MAC address locally, while DNS spoofing operates at the Application layer to map a domain name to a wrong IP address.


Why is IP forwarding necessary during an ARP poisoning attack?

Without IP forwarding enabled on the attacker's machine, the intercepted traffic would stop there, causing a Denial of Service (DoS) instead of a transparent Man-in-the-Middle attack.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand ARP Poisoning? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium