N10-009 exam dumps

N10-009 practice question 261 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 261

Single answer4.2 Summarize various types of attacks and their impact to the network.

A network administrator notices that several internal users are being redirected to a fake payroll website after entering the correct company URL in their browsers. The legitimate payroll web server is functioning normally, and the issue affects users on multiple VLANs. A packet capture shows users are receiving incorrect IP address responses for the payroll site name, even though no changes were made to the internal DNS server records. Which type of attack is the MOST likely cause of this issue?

  1. A

    DNS poisoning

  2. B

    VLAN hopping

  3. C

    MAC flooding

  4. D

    Evil twin attack

Show answer and explanation

Correct answer: A

Explanation

The best answer is DNS poisoning. The key indicators are: users type the correct URL, the real payroll server is still available, and packet captures show incorrect IP address responses for the payroll hostname. That combination indicates the attack is targeting name resolution rather than the application server itself. DNS poisoning can occur on a recursive resolver, through spoofed DNS replies, or through compromise of a host or network device involved in DNS forwarding. Its impact is significant because it can redirect users to credential-harvesting sites, malware delivery pages, or attacker-controlled services without requiring users to notice a change in the URL they entered. CompTIA Network+ expects candidates to recognize attack symptoms and map them to likely attack types. Industry best practices for reducing DNS poisoning risk include using DNSSEC where supported, restricting recursive resolver access, patching DNS infrastructure, monitoring DNS logs for anomalous responses, and validating resolver behavior. Guidance from organizations such as CISA and NIST commonly emphasizes DNS integrity, logging, patch management, and layered defenses against spoofing and redirection attacks.

  • A. Correct.

    Correct. DNS poisoning, also called DNS cache poisoning, occurs when false DNS information is inserted into a DNS cache or response path so clients are directed to an incorrect IP address. In this scenario, users enter the correct payroll URL but are sent to a fraudulent site because they receive bad name resolution data. The fact that the legitimate web server is still operating normally and that multiple VLANs are affected points to a name-resolution issue rather than a server outage or local endpoint problem.

  • B. Incorrect.

    Incorrect. VLAN hopping is an attack used to gain unauthorized access to traffic on another VLAN, typically through switch spoofing or double-tagging. While it can expose traffic segmentation weaknesses, it would not normally cause users across multiple VLANs to resolve a valid hostname to a fraudulent IP address. This option is plausible because the problem spans VLANs, but the symptom specifically indicates tampered DNS responses.

  • C. Incorrect.

    Incorrect. MAC flooding overwhelms a switch's CAM table so the switch may begin flooding frames out multiple ports, potentially allowing packet sniffing. This attack affects Layer 2 switching behavior and confidentiality of traffic, but it does not directly alter DNS responses or cause clients to be redirected to a fake website by hostname resolution.

  • D. Incorrect.

    Incorrect. An evil twin attack involves a rogue wireless access point impersonating a legitimate SSID to trick users into connecting through an attacker-controlled network. Although that can enable redirection or credential theft, the scenario affects users on multiple VLANs and specifically mentions incorrect IP address responses to DNS queries. That evidence more strongly supports DNS poisoning than a wireless-specific impersonation attack.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam