CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A network administrator notices that users attempting to reach the company's legitimate banking portal are being redirected to a fraudulent site that harvests credentials, even though the URL typed into the browser is correct. Which attack technique is most likely responsible?

  1. ASession hijacking
  2. BTyposquatting
  3. CDNS poisoning
  4. DDomain hijacking
Show answer & explanation

Correct answer: C. DNS poisoning

DNS poisoning (cache poisoning) corrupts DNS resolver records so that a correctly typed domain name resolves to a malicious IP address, redirecting users without any change to the URL itself.

Why the other options are wrong

  • A. Session hijacking takes over an existing authenticated session, not DNS resolution.
  • B. Typosquatting relies on users mistyping the URL, but here the URL was correct.
  • D. Domain hijacking involves taking over ownership/registration of the actual domain, not corrupting DNS cache.

DNS Poisoning

An attack that corrupts DNS cache or records so that a domain name resolves to an attacker-controlled IP address instead of the legitimate one.

  • Also called DNS cache poisoning
  • Redirects even correctly typed URLs
  • Mitigated by DNSSEC and secure resolver configuration

Memory trick: Poison the map, and everyone walks to the wrong destination.

More Threats, Vulnerabilities, and Mitigations questions