CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A security team notices a spike in DNS queries for domains that are nearly identical to the company's legitimate domain but with a single character transposed (e.g., compnay-example.com instead of company-example.com). Employees receiving emails from these lookalike domains are being tricked into wiring funds. Which technique is being used against the organization?
- APretexting
- BDNS poisoning
- CARP spoofing
- DTyposquatting
Show answer & explanationAnswer & explanation
Correct answer: D. Typosquatting
Registering domains that closely resemble a legitimate domain, differing by transposed or misspelled characters, to deceive victims is known as typosquatting, often used to support business email compromise or phishing campaigns.
Why the other options are wrong
- A. Pretexting is a social engineering technique using a fabricated scenario, not domain-based deception.
- B. DNS poisoning corrupts DNS cache/resolution records, not registration of similar-looking domains.
- C. ARP spoofing manipulates local network address resolution, unrelated to domain registration.
Typosquatting
A technique where attackers register domain names similar to legitimate ones (misspellings, transpositions) to deceive users, often for phishing or fraud.
- Often combined with BEC or phishing emails
- Relies on visual similarity to trick recipients
- Mitigated by defensive domain registration and email domain monitoring
Memory trick: Swap two letters and slip past the eye — typo becomes trap.