N10-009 exam dumps

N10-009 practice question 265 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 265

Single answerVLAN hopping, Media Access Control (MAC) flooding, Address Resolution Protocol (ARP) poisoning, ARP spoofing, DNS poisoning, DNS spoofing

A network administrator is investigating reports that users are intermittently redirected to a fake internal payroll website, even though the DNS server configuration on client PCs has not changed. Packet captures from affected hosts show unsolicited ARP replies claiming that the default gateway's IP address is associated with the attacker's MAC address. Users can still reach some internal resources, but traffic to the payroll site is being intercepted and altered. Which attack is MOST directly enabling this man-in-the-middle scenario?

  1. A

    VLAN hopping

  2. B

    MAC flooding

  3. C

    ARP spoofing

  4. D

    DNS poisoning

Show answer and explanation

Correct answer: C

Explanation

The best answer is ARP spoofing. The scenario provides the most important forensic clue: unsolicited ARP replies claiming that the default gateway's IP address belongs to the attacker's MAC address. That is the hallmark of ARP spoofing/ARP poisoning, which is a common Layer 2 man-in-the-middle technique on IPv4 LANs. Once the attacker inserts themselves between clients and the gateway, they can intercept and alter traffic, including web sessions and even DNS requests or responses in transit.

This question distinguishes between related but different attacks. VLAN hopping is about crossing VLAN boundaries, not impersonating the gateway. MAC flooding targets the switch's MAC address table, potentially causing frame flooding, but it does not inherently rely on forged ARP ownership claims. DNS poisoning could also cause redirection to a fake site, but the scenario specifically identifies manipulated ARP behavior as the direct enabler of the attack path.

From a best-practice perspective, defenses against ARP spoofing include Dynamic ARP Inspection (DAI), DHCP snooping, static ARP entries for critical systems where appropriate, switch port security, and use of encrypted protocols such as HTTPS to reduce the impact of interception. These mitigations are consistent with common enterprise switching security guidance from major network vendors and standard secure network design practices.

  • A. Incorrect.

    VLAN hopping is incorrect. VLAN hopping is an attack used to gain access to traffic on another VLAN, typically through switch spoofing or double-tagging. In this scenario, the key evidence is unsolicited ARP replies that map the gateway IP address to the attacker's MAC address, which points to Layer 2 address manipulation on the local segment rather than unauthorized traversal between VLANs.

  • B. Incorrect.

    MAC flooding is incorrect. MAC flooding attempts to overwhelm a switch's CAM table so the switch begins flooding frames out multiple ports, potentially allowing an attacker to sniff traffic. While that can expose traffic, it does not specifically explain the observed forged ARP replies claiming ownership of the default gateway's IP address. The scenario describes active redirection through falsified ARP mappings, not CAM table exhaustion.

  • C. Correct.

    ARP spoofing is correct. ARP spoofing, also called ARP poisoning, occurs when an attacker sends forged ARP messages to associate their MAC address with another device's IP address, commonly the default gateway. This allows the attacker to place themselves between the victim and the gateway to intercept, inspect, or modify traffic. The unsolicited ARP replies and the gateway-IP-to-attacker-MAC mapping are classic indicators of this attack.

  • D. Incorrect.

    DNS poisoning is incorrect. DNS poisoning involves corrupting DNS data so a domain name resolves to the wrong IP address, often through cache poisoning or falsified DNS responses. Although users are being redirected to a fake payroll site, the scenario explicitly states that packet captures show forged ARP replies binding the gateway IP to the attacker's MAC, indicating that the underlying man-in-the-middle access is being established through ARP spoofing rather than DNS manipulation.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam