CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A network administrator notices that users attempting to reach the company's legitimate banking portal are being redirected to a fraudulent site that harvests credentials, even though the URL typed into the browser is correct. Which attack technique is most likely responsible?
- ASession hijacking
- BTyposquatting
- CDNS poisoning
- DDomain hijacking
Show answer & explanationAnswer & explanation
Correct answer: C. DNS poisoning
DNS poisoning (cache poisoning) corrupts DNS resolver records so that a correctly typed domain name resolves to a malicious IP address, redirecting users without any change to the URL itself.
Why the other options are wrong
- A. Session hijacking takes over an existing authenticated session, not DNS resolution.
- B. Typosquatting relies on users mistyping the URL, but here the URL was correct.
- D. Domain hijacking involves taking over ownership/registration of the actual domain, not corrupting DNS cache.
DNS Poisoning
An attack that corrupts DNS cache or records so that a domain name resolves to an attacker-controlled IP address instead of the legitimate one.
- Also called DNS cache poisoning
- Redirects even correctly typed URLs
- Mitigated by DNSSEC and secure resolver configuration
Memory trick: Poison the map, and everyone walks to the wrong destination.