CompTIA Network+ N10-009 Network Attacks Spoofing Rogue Services And Social Engineering Practice Test

 

Objective 4.2 • 25 original questions

This CompTIA Network+ N10-009 practice test focuses on network attacks and their impact. All questions are original ExamSnap scenarios aligned to the current N10-009 blueprint; they are not copied from CompTIA exam content. Use the complete N10-009 collection for broader practice across all five domains. For broader exam preparation, review the CompTIA Network+ N10-009 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to identify an attack whose primary objective is exhausting availability or capacity. Which option is the best fit? The decision applies to a branch-office rollout.

  1. DoS/DDoS
  2. Shoulder surfing
  3. DNS spoofing
  4. On-path attack
  5. ARP poisoning/spoofing

Correct answer: A

Why: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: identify an attack whose primary objective is exhausting availability or capacity.

Option review:

A: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: identify an attack whose primary objective is exhausting availability or capacity.

B: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.

C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.

D: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify an attack whose primary objective is exhausting availability or capacity.

Learning point: Use DoS/DDoS when the key requirement is to identify an attack whose primary objective is exhausting availability or capacity.

Question 2

A ticket at Woodgrove Bank says the team must identify an attack targeting VLAN segmentation boundaries. Which technology or concept most directly addresses this requirement? The decision applies to a campus refresh.

  1. ARP poisoning/spoofing
  2. Shoulder surfing
  3. VLAN hopping
  4. Tailgating
  5. DNS poisoning

Correct answer: C

Why: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: identify an attack targeting VLAN segmentation boundaries.

Option review:

A: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.

B: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.

C: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: identify an attack targeting VLAN segmentation boundaries.

D: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.

E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify an attack targeting VLAN segmentation boundaries.

Learning point: Use VLAN hopping when the key requirement is to identify an attack targeting VLAN segmentation boundaries.

Question 3

During a design meeting at Blue Yonder Airlines, the junior network administrator needs to identify an attack that fills a switch MAC-address table. What should be selected? The decision applies to a data-center segment.

  1. Shoulder surfing
  2. Evil twin
  3. MAC flooding
  4. DNS spoofing
  5. Malware

Correct answer: C

Why: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: identify an attack that fills a switch MAC-address table.

Option review:

A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.

B: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.

C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: identify an attack that fills a switch MAC-address table.

D: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.

E: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: identify an attack that fills a switch MAC-address table.

Learning point: Use MAC flooding when the key requirement is to identify an attack that fills a switch MAC-address table.

Question 4

Contoso Health is updating its network standard. Which option best meets the need to identify manipulation of local ARP mappings used for man-in-the-middle traffic? The decision applies to a remote-site migration.

  1. On-path attack
  2. MAC flooding
  3. Phishing
  4. Evil twin
  5. ARP poisoning/spoofing

Correct answer: E

Why: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

Option review:

A: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

B: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

C: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: identify manipulation of local ARP mappings used for man-in-the-middle traffic.

Learning point: Use ARP poisoning/spoofing when the key requirement is to identify manipulation of local ARP mappings used for man-in-the-middle traffic.

Question 5

A field technician at Litware Manufacturing is validating a proposed solution. The design must identify corruption of cached DNS answers. Which answer is most appropriate? The decision applies to a operations lab.

  1. DNS poisoning
  2. Rogue DHCP server
  3. DoS/DDoS
  4. Evil twin
  5. Tailgating

Correct answer: A

Why: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: identify corruption of cached DNS answers.

Option review:

A: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: identify corruption of cached DNS answers.

B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.

C: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.

D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.

E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify corruption of cached DNS answers.

Learning point: Use DNS poisoning when the key requirement is to identify corruption of cached DNS answers.

Question 6

For a new deployment at Woodgrove Bank, the networking team wants to identify forged DNS replies intended to redirect clients. Which choice most directly satisfies the goal? The decision applies to a production maintenance window.

  1. Shoulder surfing
  2. DoS/DDoS
  3. Dumpster diving
  4. DNS spoofing
  5. ARP poisoning/spoofing

Correct answer: D

Why: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: identify forged DNS replies intended to redirect clients.

Option review:

A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.

B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.

C: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.

D: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: identify forged DNS replies intended to redirect clients.

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify forged DNS replies intended to redirect clients.

Learning point: Use DNS spoofing when the key requirement is to identify forged DNS replies intended to redirect clients.

Question 7

At Blue Yonder Airlines, a systems administrator is reviewing a network change. The requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service. Which option is the best fit? The decision applies to a new floor deployment.

  1. On-path attack
  2. Rogue DHCP server
  3. MAC flooding
  4. VLAN hopping
  5. DNS poisoning

Correct answer: B

Why: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

Option review:

A: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

D: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

Learning point: Use Rogue DHCP server when the key requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

Question 8

A ticket at Contoso Health says the team must identify an unapproved wireless device providing network access. Which technology or concept most directly addresses this requirement? The decision applies to a service-recovery review.

  1. DNS poisoning
  2. Rogue DHCP server
  3. Rogue access point
  4. Dumpster diving
  5. Phishing

Correct answer: C

Why: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: identify an unapproved wireless device providing network access.

Option review:

A: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.

B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.

C: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: identify an unapproved wireless device providing network access.

D: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.

E: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify an unapproved wireless device providing network access.

Learning point: Use Rogue access point when the key requirement is to identify an unapproved wireless device providing network access.

Question 9

During a design meeting at Litware Manufacturing, the junior network administrator needs to identify a fake Wi-Fi network designed to impersonate a trusted WLAN. What should be selected? The decision applies to a branch-office rollout.

  1. Shoulder surfing
  2. Phishing
  3. Evil twin
  4. DoS/DDoS
  5. DNS spoofing

Correct answer: C

Why: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

Option review:

A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

B: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

C: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

D: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

E: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

Learning point: Use Evil twin when the key requirement is to identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

Question 10

Woodgrove Bank is updating its network standard. Which option best meets the need to identify interception/modification of traffic while both endpoints believe they communicate normally? The decision applies to a campus refresh.

  1. Phishing
  2. Rogue DHCP server
  3. On-path attack
  4. Shoulder surfing
  5. Rogue access point

Correct answer: C

Why: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: identify interception/modification of traffic while both endpoints believe they communicate normally.

Option review:

A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.

B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.

C: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: identify interception/modification of traffic while both endpoints believe they communicate normally.

D: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.

E: An unauthorized AP is connected to the organization network. However, it does not most directly satisfy the requirement in this scenario: identify interception/modification of traffic while both endpoints believe they communicate normally.

Learning point: Use On-path attack when the key requirement is to identify interception/modification of traffic while both endpoints believe they communicate normally.

Question 11

A field technician at Blue Yonder Airlines is validating a proposed solution. The design must identify a fraudulent email or message designed to steal credentials. Which answer is most appropriate? The decision applies to a data-center segment.

  1. Phishing
  2. DNS poisoning
  3. MAC flooding
  4. On-path attack
  5. Tailgating

Correct answer: A

Why: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. This directly satisfies the requirement: identify a fraudulent email or message designed to steal credentials.

Option review:

A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. This directly satisfies the requirement: identify a fraudulent email or message designed to steal credentials.

B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.

C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.

D: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.

E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: identify a fraudulent email or message designed to steal credentials.

Learning point: Use Phishing when the key requirement is to identify a fraudulent email or message designed to steal credentials.

Question 12

For a new deployment at Contoso Health, the networking team wants to identify retrieval of confidential information from trash or discarded media. Which choice most directly satisfies the goal? The decision applies to a remote-site migration.

  1. Phishing
  2. Dumpster diving
  3. DoS/DDoS
  4. Evil twin
  5. ARP poisoning/spoofing

Correct answer: B

Why: Obtains sensitive information from discarded physical materials or devices. This directly satisfies the requirement: identify retrieval of confidential information from trash or discarded media.

Option review:

A: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.

B: Obtains sensitive information from discarded physical materials or devices. This directly satisfies the requirement: identify retrieval of confidential information from trash or discarded media.

C: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.

D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify retrieval of confidential information from trash or discarded media.

Learning point: Use Dumpster diving when the key requirement is to identify retrieval of confidential information from trash or discarded media.

Question 13

At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to identify theft of information by watching someone type or view it. Which option is the best fit? The decision applies to a operations lab.

  1. VLAN hopping
  2. DNS spoofing
  3. Phishing
  4. Shoulder surfing
  5. Evil twin

Correct answer: D

Why: Observes a user entering or viewing sensitive information. This directly satisfies the requirement: identify theft of information by watching someone type or view it.

Option review:

A: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.

B: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.

C: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.

D: Observes a user entering or viewing sensitive information. This directly satisfies the requirement: identify theft of information by watching someone type or view it.

E: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: identify theft of information by watching someone type or view it.

Learning point: Use Shoulder surfing when the key requirement is to identify theft of information by watching someone type or view it.

Question 14

A ticket at Woodgrove Bank says the team must identify bypass of physical access controls by following an employee through a secure door. Which technology or concept most directly addresses this requirement? The decision applies to a production maintenance window.

  1. Tailgating
  2. DoS/DDoS
  3. DNS spoofing
  4. ARP poisoning/spoofing
  5. DNS poisoning

Correct answer: A

Why: An unauthorized person follows an authorized person through a controlled physical entrance. This directly satisfies the requirement: identify bypass of physical access controls by following an employee through a secure door.

Option review:

A: An unauthorized person follows an authorized person through a controlled physical entrance. This directly satisfies the requirement: identify bypass of physical access controls by following an employee through a secure door.

B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.

C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.

D: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.

E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: identify bypass of physical access controls by following an employee through a secure door.

Learning point: Use Tailgating when the key requirement is to identify bypass of physical access controls by following an employee through a secure door.

Question 15

During a design meeting at Blue Yonder Airlines, the junior network administrator needs to identify malicious code running on a host as the attack mechanism. What should be selected? The decision applies to a new floor deployment.

  1. Shoulder surfing
  2. ARP poisoning/spoofing
  3. MAC flooding
  4. VLAN hopping
  5. Malware

Correct answer: E

Why: Malicious software can disrupt, spy, steal, or provide unauthorized control. This directly satisfies the requirement: identify malicious code running on a host as the attack mechanism.

Option review:

A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.

B: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.

C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.

D: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: identify malicious code running on a host as the attack mechanism.

E: Malicious software can disrupt, spy, steal, or provide unauthorized control. This directly satisfies the requirement: identify malicious code running on a host as the attack mechanism.

Learning point: Use Malware when the key requirement is to identify malicious code running on a host as the attack mechanism.

Question 16

During a data-center segment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources.

  1. Shoulder surfing
  2. VLAN hopping
  3. DNS spoofing
  4. DoS/DDoS
  5. ARP poisoning/spoofing

Correct answer: D

Why: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

Option review:

A: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

B: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

D: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. This directly satisfies the requirement: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources..

Learning point: Use DoS/DDoS when the key requirement is to identify an attack whose primary objective is exhausting availability or capacity.

Question 17

During a remote-site migration, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to.

  1. VLAN hopping
  2. On-path attack
  3. MAC flooding
  4. Tailgating
  5. Shoulder surfing

Correct answer: A

Why: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

Option review:

A: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to. This directly satisfies the requirement: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

B: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

C: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

D: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

E: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: Attempts to reach traffic on VLANs the attacker is not legitimately assigned to..

Learning point: Use VLAN hopping when the key requirement is to identify an attack targeting VLAN segmentation boundaries.

Question 18

During a operations lab, Woodgrove Bank is comparing several networking concepts. Which option is accurately characterized by this statement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly.

  1. MAC flooding
  2. DNS poisoning
  3. On-path attack
  4. Malware
  5. ARP poisoning/spoofing

Correct answer: A

Why: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

Option review:

A: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. This directly satisfies the requirement: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

C: An attacker positions between communicating parties to observe or alter traffic. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

D: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

E: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Overloads a switch CAM/MAC table so traffic may be flooded more broadly..

Learning point: Use MAC flooding when the key requirement is to identify an attack that fills a switch MAC-address table.

Question 19

During a production maintenance window, Blue Yonder Airlines is comparing several networking concepts. Which option is accurately characterized by this statement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception.

  1. Malware
  2. MAC flooding
  3. Tailgating
  4. ARP poisoning/spoofing
  5. DoS/DDoS

Correct answer: D

Why: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

Option review:

A: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

B: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

C: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

D: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. This directly satisfies the requirement: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

E: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception..

Learning point: Use ARP poisoning/spoofing when the key requirement is to identify manipulation of local ARP mappings used for man-in-the-middle traffic.

Question 20

During a new floor deployment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses.

  1. Malware
  2. DNS poisoning
  3. DNS spoofing
  4. Phishing
  5. Tailgating

Correct answer: B

Why: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

Option review:

A: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. This directly satisfies the requirement: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

D: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

E: An unauthorized person follows an authorized person through a controlled physical entrance. However, it does not most directly satisfy the requirement in this scenario: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses..

Learning point: Use DNS poisoning when the key requirement is to identify corruption of cached DNS answers.

Question 21

During a service-recovery review, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: Provides forged DNS responses to redirect users to incorrect destinations.

  1. ARP poisoning/spoofing
  2. DNS poisoning
  3. DNS spoofing
  4. Dumpster diving
  5. MAC flooding

Correct answer: C

Why: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: Provides forged DNS responses to redirect users to incorrect destinations..

Option review:

A: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..

B: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..

C: Provides forged DNS responses to redirect users to incorrect destinations. This directly satisfies the requirement: Provides forged DNS responses to redirect users to incorrect destinations..

D: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..

E: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: Provides forged DNS responses to redirect users to incorrect destinations..

Learning point: Use DNS spoofing when the key requirement is to identify forged DNS replies intended to redirect clients.

Question 22

During a branch-office rollout, Woodgrove Bank is comparing several networking concepts. Which option is accurately characterized by this statement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients.

  1. MAC flooding
  2. Malware
  3. DNS spoofing
  4. Rogue DHCP server
  5. DNS poisoning

Correct answer: D

Why: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

Option review:

A: Overloads a switch CAM/MAC table so traffic may be flooded more broadly. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

B: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

C: Provides forged DNS responses to redirect users to incorrect destinations. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

D: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. This directly satisfies the requirement: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

E: Introduces false DNS data into resolver/cache state so names resolve to malicious addresses. However, it does not most directly satisfy the requirement in this scenario: An unauthorized DHCP server provides malicious or incorrect network configuration to clients..

Learning point: Use Rogue DHCP server when the key requirement is to identify clients receiving incorrect gateway/DNS settings from an unauthorized service.

Question 23

During a campus refresh, Blue Yonder Airlines is comparing several networking concepts. Which option is accurately characterized by this statement: An unauthorized AP is connected to the organization network.

  1. Rogue DHCP server
  2. Malware
  3. Evil twin
  4. Rogue access point
  5. Shoulder surfing

Correct answer: D

Why: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: An unauthorized AP is connected to the organization network..

Option review:

A: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..

B: Malicious software can disrupt, spy, steal, or provide unauthorized control. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..

C: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..

D: An unauthorized AP is connected to the organization network. This directly satisfies the requirement: An unauthorized AP is connected to the organization network..

E: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: An unauthorized AP is connected to the organization network..

Learning point: Use Rogue access point when the key requirement is to identify an unapproved wireless device providing network access.

Question 24

During a data-center segment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: A malicious AP imitates a legitimate SSID to lure users into connecting.

  1. Dumpster diving
  2. Rogue DHCP server
  3. Evil twin
  4. Shoulder surfing
  5. Phishing

Correct answer: C

Why: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: A malicious AP imitates a legitimate SSID to lure users into connecting..

Option review:

A: Obtains sensitive information from discarded physical materials or devices. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..

B: An unauthorized DHCP server provides malicious or incorrect network configuration to clients. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..

C: A malicious AP imitates a legitimate SSID to lure users into connecting. This directly satisfies the requirement: A malicious AP imitates a legitimate SSID to lure users into connecting..

D: Observes a user entering or viewing sensitive information. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..

E: Uses deceptive messages/sites to trick users into revealing information or executing malicious actions. However, it does not most directly satisfy the requirement in this scenario: A malicious AP imitates a legitimate SSID to lure users into connecting..

Learning point: Use Evil twin when the key requirement is to identify a fake Wi-Fi network designed to impersonate a trusted WLAN.

Question 25

During a remote-site migration, Litware Manufacturing is comparing several networking concepts. Which option is accurately characterized by this statement: An attacker positions between communicating parties to observe or alter traffic.

  1. Rogue access point
  2. DoS/DDoS
  3. ARP poisoning/spoofing
  4. Evil twin
  5. On-path attack

Correct answer: E

Why: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: An attacker positions between communicating parties to observe or alter traffic..

Option review:

A: An unauthorized AP is connected to the organization network. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..

B: Overwhelms a service or resource so legitimate users cannot access it; DDoS uses many distributed sources. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..

C: Sends forged ARP information to associate an attacker MAC address with another host/IP, enabling interception. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..

D: A malicious AP imitates a legitimate SSID to lure users into connecting. However, it does not most directly satisfy the requirement in this scenario: An attacker positions between communicating parties to observe or alter traffic..

E: An attacker positions between communicating parties to observe or alter traffic. This directly satisfies the requirement: An attacker positions between communicating parties to observe or alter traffic..

Learning point: Use On-path attack when the key requirement is to identify interception/modification of traffic while both endpoints believe they communicate normally.

Popular posts

img