CompTIA Network+ (N10-009)Network SecurityHard
Users report being redirected to a fraudulent banking website even though they typed the correct URL directly into their browser. Investigation reveals that the organization's DNS resolver contains a fake IP address mapped to the bank's legitimate domain name. Which attack has occurred?
- AEvil twin attack
- BVLAN hopping
- CARP spoofing
- DDNS cache poisoning
Show answer & explanationAnswer & explanation
Correct answer: D. DNS cache poisoning
DNS cache poisoning occurs when an attacker injects a forged DNS record into a resolver's cache, causing legitimate domain name lookups to return a malicious IP address. Because the resolver itself is compromised, even correctly typed URLs redirect victims to the attacker's server.
Why the other options are wrong
- A. An evil twin is a rogue wireless AP mimicking a legitimate SSID, unrelated to DNS resolution.
- B. VLAN hopping exploits trunking misconfiguration to access unauthorized VLANs, not DNS records.
- C. ARP spoofing operates at Layer 2 within a local subnet and doesn't corrupt DNS name resolution.
DNS Cache Poisoning
An attack that injects falsified DNS resolution data into a resolver's cache, redirecting legitimate domain lookups to malicious IP addresses.
- Also called DNS spoofing
- Exploits weak transaction ID randomization or race conditions
- Mitigated by DNSSEC, source port randomization, and short TTLs
Memory trick: Poison the cache, and every visitor drinks from the wrong well.