Dynamic Host Configuration Protocol (DHCP)
The protocol that leases IP addresses and settings such as the default gateway and DNS servers to hosts automatically, with no authentication of the server by default.
The Dynamic Host Configuration Protocol, defined for IPv4 in RFC 2131 and for IPv6 in RFC 8415, hands a joining host its network configuration: an IP address for a fixed lease period, plus the subnet mask, the default gateway and the DNS servers to use. The IPv4 exchange is commonly remembered by its four messages: Discover, Offer, Request and Acknowledge. A client that reaches no server may fall back to a self-assigned APIPA address.
The security weakness is trust. A client commonly accepts the first offer it receives, and classic DHCP does not authenticate the server. A rogue DHCP server on the segment can therefore hand out its own address as the gateway or DNS server, placing the attacker in the path as a man-in-the-middle. DHCP starvation, requesting leases from many forged MAC addresses until the pool is empty, often prepares the way for the rogue server. The common control is DHCP snooping on the switch, which allows server replies only from ports an administrator marks as trusted and can limit the rate of requests.
Exam relevance: a scenario is likely to describe hosts receiving an unexpected gateway or DNS server, which points to a rogue DHCP server rather than a routing fault. Candidates are expected to connect DHCP snooping, a switch control, with that threat.