CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A user on a coffee shop's public Wi-Fi network reports that their browser displayed a certificate warning while accessing their bank's website. An analyst reviewing network traffic finds that an attacker's laptop is positioned between the user and the wireless access point, intercepting and relaying traffic while presenting a forged certificate. Which type of attack is described?
- AOn-path (man-in-the-middle) attack
- BReplay attack
- CARP spoofing
- DDNS poisoning
Show answer & explanationAnswer & explanation
Correct answer: A. On-path (man-in-the-middle) attack
An on-path attack occurs when an attacker positions themselves between two communicating parties to intercept, and potentially alter, traffic; presenting a forged certificate to intercept HTTPS traffic is a classic sign of this. ARP spoofing is one technique that can be used to achieve an on-path position, but the question describes the resulting interception scenario itself, which is best classified as on-path/MITM.
Why the other options are wrong
- B. Wrong: replay attacks resend captured data later, not real-time interception.
- C. Wrong: ARP spoofing is a specific method to achieve interception on a LAN, but the scenario describes the broader interception, not the ARP mechanism.
- D. Wrong: DNS poisoning redirects domain resolution, not direct traffic interception with a forged cert.
On-Path (Man-in-the-Middle) Attack
An attack where the threat actor secretly intercepts and possibly alters communication between two parties who believe they are directly communicating.
- Often involves forged certificates or ARP spoofing to position the attacker
- Common on unsecured public Wi-Fi networks
- Mitigated with HTTPS/TLS validation, VPNs, and certificate pinning
Memory trick: The attacker stands 'on the path' between you and your bank.