N10-009 exam dumps

N10-009 practice question 267 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 267

Single answerRogue devices and services: DHCP, AP, Evil twin, On-path attack

Users in a branch office report intermittent connectivity problems after a visitor was seen working in a conference room. Some clients receive IP addresses in the 10.10.50.0/24 range instead of the corporate 10.10.20.0/24 range. A packet capture shows those affected clients receive DHCPOFFER messages faster from an unknown MAC address than from the authorized Windows DHCP server. After accepting the lease, the clients use a default gateway of 10.10.50.1 and are redirected to fake login pages for several internal web applications. Which issue BEST explains this behavior?

  1. A

    A rogue DHCP server is performing an on-path attack by supplying attacker-controlled addressing information

  2. B

    A misconfigured split-scope DHCP deployment is assigning overlapping address pools

  3. C

    An evil twin access point is broadcasting the same SSID as the corporate wireless network

  4. D

    A rogue access point is extending the wired network but is not modifying Layer 3 settings

Show answer and explanation

Correct answer: A

Explanation

This scenario describes a rogue DHCP server. In DHCP, clients typically accept the first valid offer they receive, so an attacker can exploit that behavior by responding faster than the legitimate server. By assigning a malicious default gateway and possibly DNS servers, the attacker can place themselves in the traffic path, which is a classic on-path attack technique. The fake login pages further support traffic interception or redirection after the client adopts the rogue configuration. From an operational and security best-practice perspective, this is why organizations use controls such as DHCP snooping on managed switches, port security, NAC, and regular monitoring for unauthorized services and MAC addresses. Vendor and standards-based guidance commonly recommends DHCP snooping specifically to block untrusted ports from sending DHCPOFFER and DHCPACK messages, helping prevent rogue DHCP attacks.

  • A. Correct.

    Correct. The key evidence is that clients are accepting DHCPOFFER messages from an unknown MAC address and receiving a different subnet and attacker-controlled default gateway. A rogue DHCP server can win the DHCP race by responding faster than the legitimate server. By handing out its own gateway and DNS information, the attacker can place traffic through a system they control, enabling an on-path attack and redirection to fake login pages.

  • B. Incorrect.

    Incorrect. Split-scope DHCP is a legitimate high-availability design in which multiple authorized DHCP servers share a scope. While a misconfiguration could cause address conflicts or inconsistent leases, it would not typically involve an unknown MAC address responding first, nor would it explain deliberate redirection to fake login pages through an attacker-controlled gateway.

  • C. Incorrect.

    Incorrect. An evil twin is a fraudulent wireless access point that imitates a legitimate SSID to lure wireless clients into associating to it. In this scenario, the strongest indicator is unauthorized DHCP behavior on the network segment, not client association to a fake WLAN. An evil twin could also facilitate credential theft, but the question specifically points to rogue DHCPOFFERs and malicious IP configuration.

  • D. Incorrect.

    Incorrect. A rogue access point connected to the wired network can be a security risk, but if it is only bridging traffic and not providing DHCP or changing Layer 3 parameters, it would not explain clients receiving leases in the wrong subnet or being assigned a malicious default gateway. The attack described depends on unauthorized DHCP service altering host network settings.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam