A security administrator suspects a MITM attack aimed at impersonating the default gateway is underway. Which of the following tools should the administrator use to detect this attack?
a) ARP poisoning detection tool
b) Packet sniffer
c) Intrusion Detection System (IDS)
d) Network scanner