Address Resolution Protocol (ARP)
The protocol an IPv4 host uses to learn the hardware (MAC) address that belongs to an IP address on its own segment; it has no authentication, which is what ARP spoofing exploits.
The Address Resolution Protocol, defined in RFC 826, resolves an IPv4 address to the hardware address of a host on the same local segment. A host that wants to send to a local address, or to its default gateway, broadcasts a request asking which device holds that address. The owner replies with its MAC address, and the sender keeps the answer in its ARP cache for a limited time. ARP links layer 3 addressing to layer 2 delivery in the OSI model, and its requests do not cross a router. IPv6 does not use ARP; it does the same job with Neighbor Discovery.
ARP has no authentication. Hosts commonly accept unsolicited replies and gratuitous announcements and update their caches, so any device on the segment can claim any address. That design gap is the basis of ARP spoofing, which puts an attacker in the path of local traffic as a man-in-the-middle. The defences sit on the switch and the network rather than in the protocol: dynamic ARP inspection, static entries for critical hosts, and keeping unknown devices off the segment.
Exam relevance: questions in this area tend to turn on layer and scope. ARP answers “which MAC address holds this IP address” on the local network only, and its lack of authentication is the reason spoofing works.