A corporate network administrator has noticed unusual traffic patterns suggesting that someone may be intercepting and potentially altering the data between two endpoints on their network. Which of the following would be the MOST likely indicator that an on-path attack is occurring?
An increase in ICMP traffic throughout the network.
Unusual account lockouts from multiple user accounts.
Unusual inconsistencies in ARP tables across devices on the network.
SSL certificate mismatch notices on internal websites.