N10-009 exam dumps

N10-009 practice question 262 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 262

Single answer4.2 Summarize various types of attacks and their impact to the network.

A network administrator notices that several internal users are being redirected to a fake payroll website after entering the correct company URL in their browsers. The issue affects multiple devices across the same subnet, and packet captures show normal HTTP/HTTPS traffic going to an unexpected external IP address. The company's web server and public DNS records have not been changed. Which type of attack is the MOST likely cause of this issue?

  1. A

    DNS poisoning

  2. B

    VLAN hopping

  3. C

    MAC flooding

  4. D

    ARP spoofing

Show answer and explanation

Correct answer: D

Explanation

The best answer is ARP spoofing. In a local subnet, hosts rely on ARP to map IP addresses to MAC addresses. If an attacker poisons ARP caches, clients may send traffic intended for the default gateway to the attacker's device instead. This enables interception, redirection, or modification of traffic, which is a classic on-path/man-in-the-middle attack. The subnet-limited impact is an important clue: if the problem were due to public DNS tampering, it would more likely affect a broader set of users beyond a single subnet. Network security best practices recommend using tools such as dynamic ARP inspection (DAI), DHCP snooping, port security, segmentation, and encrypted protocols to reduce the risk and impact of ARP-based attacks. These mitigations are consistent with common enterprise switch security guidance from vendors such as Cisco and with general industry best practices for defending against Layer 2 attacks.

  • A. Incorrect.

    DNS poisoning is incorrect in this scenario because the company's public DNS records have not been changed, and the issue is limited to multiple devices on the same subnet rather than all users everywhere. DNS poisoning typically involves corrupting DNS responses or cache entries so users resolve a hostname to the wrong IP address. While the symptoms can look similar, the subnet-specific scope points more strongly to a local Layer 2 attack.

  • B. Incorrect.

    VLAN hopping is incorrect because this attack is used to gain unauthorized access to traffic on another VLAN, usually by switch spoofing or double-tagging. It does not typically cause users on the same subnet to be redirected to a fake website after typing a legitimate URL. Someone might choose this because it is a network attack involving switched environments, but it does not fit the redirection behavior described.

  • C. Incorrect.

    MAC flooding is incorrect because it attempts to overwhelm a switch's CAM table so the switch begins forwarding traffic out many ports, effectively acting more like a hub. This can enable packet sniffing, but it does not directly explain why users are being transparently redirected to a fraudulent site. It is a plausible distractor because it is a common switched-network attack, but it does not best match the observed outcome.

  • D. Correct.

    ARP spoofing is correct because an attacker on the local subnet can send forged ARP messages to associate the attacker's MAC address with the default gateway's IP address. This allows the attacker to perform a man-in-the-middle attack and redirect or proxy user traffic to a malicious destination, even when users enter the correct URL. The fact that only systems on the same subnet are affected and traffic is going to an unexpected external IP strongly supports ARP spoofing.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam