CompTIA Network+ N10-009 Network Attacks Spoofing Rogue Services And Social Engineering Practice Test
Objective 4.2 • 25 original questions
This CompTIA Network+ N10-009 practice test focuses on network attacks and their impact. All questions are original ExamSnap scenarios aligned to the current N10-009 blueprint; they are not copied from CompTIA exam content. Use the complete N10-009 collection for broader practice across all five domains. For broader exam preparation, review the CompTIA Network+ N10-009 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to identify an attack whose primary objective is exhausting availability or capacity. Which option is the best fit? The decision applies to a branch-office rollout.
Correct answer: A
Why: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: identify an attack whose primary objective is exhausting availability or capacity.
Option review:
A: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: identify an attack whose primary objective is exhausting availability or capacity.
B: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.
C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.
D: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.
Learning point: Use DoS/DDoS when the key requirement is to identify an attack whose primary objective is exhausting availability or capacity.
A ticket at Woodgrove Bank says the team must identify an attack targeting VLAN segmentation boundaries. Which technology or concept most directly addresses this requirement? The decision applies to a campus refresh.
Correct answer: C
Why: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: identify an attack targeting VLAN segmentation boundaries.
Option review:
A: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.
B: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.
C: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: identify an attack targeting VLAN segmentation boundaries.
D: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.
E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.
Learning point: Use VLAN hopping when the key requirement is to identify an attack targeting VLAN segmentation boundaries.
During a design meeting at Blue Yonder Airlines, the junior network administrator needs to identify an attack that fills a switch MAC-address table. What should be selected? The decision applies to a data-center segment.
Correct answer: C
Why: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: identify an attack that fills a switch MAC-address table.
Option review:
A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.
B: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.
C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: identify an attack that fills a switch MAC-address table.
D: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.
E: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.
Learning point: Use MAC flooding when the key requirement is to identify an attack that fills a switch MAC-address table.
Contoso Health is updating its network standard. Which option best meets the need to identify manipulation of local ARP mappings used for man-in-the-middle traffic? The decision applies to a remote-site migration.
Correct answer: E
Why: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
Option review:
A: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
B: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
C: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: identify manipulation of local ARP mappings used for man-in-the-middle traffic.
Learning point: Use ARP poisoning/spoofing when the key requirement is to identify manipulation of local ARP mappings used for man-in-the-middle traffic.
A field technician at Litware Manufacturing is validating a proposed solution. The design must identify corruption of cached DNS answers. Which answer is most appropriate? The decision applies to a operations lab.
Correct answer: A
Why: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: identify corruption of cached DNS answers.
Option review:
A: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: identify corruption of cached DNS answers.
B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.
C: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.
D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.
E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.
Learning point: Use DNS poisoning when the key requirement is to identify corruption of cached DNS answers.
For a new deployment at Woodgrove Bank, the networking team wants to identify forged DNS replies intended to redirect clients. Which choice most directly satisfies the goal? The decision applies to a production maintenance window.
Correct answer: D
Why: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: identify forged DNS replies intended to redirect clients.
Option review:
A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.
B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.
C: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.
D: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: identify forged DNS replies intended to redirect clients.
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.
Learning point: Use DNS spoofing when the key requirement is to identify forged DNS replies intended to redirect clients.
At Blue Yonder Airlines, a systems administrator is reviewing a network change. The requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service. Which option is the best fit? The decision applies to a new floor deployment.
Correct answer: B
Why: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
Option review:
A: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
D: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
Learning point: Use Rogue DHCP server when the key requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
A ticket at Contoso Health says the team must identify an unapproved wireless device providing network access. Which technology or concept most directly addresses this requirement? The decision applies to a service-recovery review.
Correct answer: C
Why: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: identify an unapproved wireless device providing network access.
Option review:
A: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.
B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.
C: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: identify an unapproved wireless device providing network access.
D: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.
E: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.
Learning point: Use Rogue access point when the key requirement is to identify an unapproved wireless device providing network access.
During a design meeting at Litware Manufacturing, the junior network administrator needs to identify a fake Wi-Fi network designed to impersonate a trusted WLAN. What should be selected? The decision applies to a branch-office rollout.
Correct answer: C
Why: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
Option review:
A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
B: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
C: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
D: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
E: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
Learning point: Use Evil twin when the key requirement is to identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
Woodgrove Bank is updating its network standard. Which option best meets the need to identify interception/modification of traffic while both endpoints believe they communicate normally? The decision applies to a campus refresh.
Correct answer: C
Why: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: identify interception/modification of traffic while both endpoints believe they communicate normally.
Option review:
A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.
B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.
C: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: identify interception/modification of traffic while both endpoints believe they communicate normally.
D: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.
E: An unauthorized AP is connected to the organization network. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.
Learning point: Use On-path attack when the key requirement is to identify interception/modification of traffic while both endpoints believe they communicate normally.
A field technician at Blue Yonder Airlines is validating a proposed solution. The design must identify a fraudulent email or message designed to steal credentials. Which answer is most appropriate? The decision applies to a data-center segment.
Correct answer: A
Why: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. This directly satisfies the requirement: identify a fraudulent email or message designed to steal credentials.
Option review:
A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. This directly satisfies the requirement: identify a fraudulent email or message designed to steal credentials.
B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.
C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.
D: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.
E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.
Learning point: Use Phishing when the key requirement is to identify a fraudulent email or message designed to steal credentials.
For a new deployment at Contoso Health, the networking team wants to identify retrieval of confidential information from trash or discarded media. Which choice most directly satisfies the goal? The decision applies to a remote-site migration.
Correct answer: B
Why: Obtains sensitive information from discarded physical materials or devices. This directly satisfies the requirement: identify retrieval of confidential information from trash or discarded media.
Option review:
A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.
B: Obtains sensitive information from discarded physical materials or devices. This directly satisfies the requirement: identify retrieval of confidential information from trash or discarded media.
C: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.
D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.
Learning point: Use Dumpster diving when the key requirement is to identify retrieval of confidential information from trash or discarded media.
At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to identify theft of information by watching someone type or view it. Which option is the best fit? The decision applies to a operations lab.
Correct answer: D
Why: Observes a user entering or viewing sensitive information. This directly satisfies the requirement: identify theft of information by watching someone type or view it.
Option review:
A: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.
B: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.
C: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.
D: Observes a user entering or viewing sensitive information. This directly satisfies the requirement: identify theft of information by watching someone type or view it.
E: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.
Learning point: Use Shoulder surfing when the key requirement is to identify theft of information by watching someone type or view it.
A ticket at Woodgrove Bank says the team must identify bypass of physical access controls by following an employee through a secure door. Which technology or concept most directly addresses this requirement? The decision applies to a production maintenance window.
Correct answer: A
Why: An unauthorized person follows an authorized person through a controlled physical entrance. This directly satisfies the requirement: identify bypass of physical access controls by following an employee through a secure door.
Option review:
A: An unauthorized person follows an authorized person through a controlled physical entrance. This directly satisfies the requirement: identify bypass of physical access controls by following an employee through a secure door.
B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.
C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.
D: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.
E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.
Learning point: Use Tailgating when the key requirement is to identify bypass of physical access controls by following an employee through a secure door.
During a design meeting at Blue Yonder Airlines, the junior network administrator needs to identify malicious code running on a host as the attack mechanism. What should be selected? The decision applies to a new floor deployment.
Correct answer: E
Why: Malicious software can disrupt, spy, steal, or provide unauthorized control. This directly satisfies the requirement: identify malicious code running on a host as the attack mechanism.
Option review:
A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.
B: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.
C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.
D: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.
E: Malicious software can disrupt, spy, steal, or provide unauthorized control. This directly satisfies the requirement: identify malicious code running on a host as the attack mechanism.
Learning point: Use Malware when the key requirement is to identify malicious code running on a host as the attack mechanism.
During a data-center segment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources.
Correct answer: D
Why: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
Option review:
A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
B: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
D: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..
Learning point: Use DoS/DDoS when the key requirement is to identify an attack whose primary objective is exhausting availability or capacity.
During a remote-site migration, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to.
Correct answer: A
Why: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
Option review:
A: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
B: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
D: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
E: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..
Learning point: Use VLAN hopping when the key requirement is to identify an attack targeting VLAN segmentation boundaries.
During a operations lab, Woodgrove Bank is comparing several networking concepts. Which option is accurately characterized by this statement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly.
Correct answer: A
Why: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
Option review:
A: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
C: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
D: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..
Learning point: Use MAC flooding when the key requirement is to identify an attack that fills a switch MAC-address table.
During a production maintenance window, Blue Yonder Airlines is comparing several networking concepts. Which option is accurately characterized by this statement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception.
Correct answer: D
Why: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
Option review:
A: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
B: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
C: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
D: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
E: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..
Learning point: Use ARP poisoning/spoofing when the key requirement is to identify manipulation of local ARP mappings used for man-in-the-middle traffic.
During a new floor deployment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses.
Correct answer: B
Why: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
Option review:
A: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
D: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..
Learning point: Use DNS poisoning when the key requirement is to identify corruption of cached DNS answers.
During a service-recovery review, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: Provides forged DNS responses to redirect users to incorrect destinations.
Correct answer: C
Why: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: Provides forged DNS responses to redirect users to incorrect destinations..
Option review:
A: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..
B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..
C: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: Provides forged DNS responses to redirect users to incorrect destinations..
D: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..
E: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..
Learning point: Use DNS spoofing when the key requirement is to identify forged DNS replies intended to redirect clients.
During a branch-office rollout, Woodgrove Bank is comparing several networking concepts. Which option is accurately characterized by this statement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients.
Correct answer: D
Why: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
Option review:
A: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
B: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
D: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..
Learning point: Use Rogue DHCP server when the key requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service.
During a campus refresh, Blue Yonder Airlines is comparing several networking concepts. Which option is accurately characterized by this statement: An unauthorized AP is connected to the organization network.
Correct answer: D
Why: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: An unauthorized AP is connected to the organization network..
Option review:
A: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..
B: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..
C: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..
D: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: An unauthorized AP is connected to the organization network..
E: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..
Learning point: Use Rogue access point when the key requirement is to identify an unapproved wireless device providing network access.
During a data-center segment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: A malicious AP imitates a legitimate SSID to lure users into connecting.
Correct answer: C
Why: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: A malicious AP imitates a legitimate SSID to lure users into connecting..
Option review:
A: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..
B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..
C: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: A malicious AP imitates a legitimate SSID to lure users into connecting..
D: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..
E: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..
Learning point: Use Evil twin when the key requirement is to identify a fake Wi-Fi network designed to impersonate a trusted WLAN.
During a remote-site migration, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: An attacker positions between communicating parties to observe or alter traffic.
Correct answer: E
Why: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: An attacker positions between communicating parties to observe or alter traffic..
Option review:
A: An unauthorized AP is connected to the organization network. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..
B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..
C: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..
D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..
E: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: An attacker positions between communicating parties to observe or alter traffic..
Learning point: Use On-path attack when the key requirement is to identify interception/modification of traffic while both endpoints believe they communicate normally.
Popular posts
Recent Posts
