While a school district is performing state testing, a security analyst notices all internet services are unavailable. The analyst discovers that ARP poisoning is occurring on the network and then terminates access for the host. Which of the following is most likely responsible for this malicious activity?
Choose an answer
Tap an option to check your answer.
Correct answer: Insider threat.
Why this is the answer
An insider threat is the most likely culprit. ARP poisoning requires direct access to the local network segment, which an insider (like a disgruntled employee, student, or contractor) would have. They could easily deploy tools to perform ARP poisoning, disrupting services. An unskilled attacker is less likely to have the necessary access or sophisticated tools to execute ARP poisoning effectively on a school district's network during state testing. Shadow IT refers to unauthorized systems or software, not typically a malicious actor performing ARP poisoning. A nation-state actor would generally employ more advanced, stealthy, and targeted attacks than a simple, disruptive ARP poisoning event during school testing, which offers little strategic value to such an actor.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed