Courseiva
Security →hardMultiple Choice

220-1202 Security Practice Question

A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?

⚠ Common exam trap

Test-takers frequently confuse DNS poisoning with ARP poisoning, because both can redirect traffic, but only DNS poisoning changes name resolution results.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS poisoning

DNS poisoning inserts false records into a DNS resolver's cache, so clients receive attacker-controlled IP addresses for legitimate names. Because DHCP and Group Policy are intact, the misdirection must come from the DNS layer. Evil twin, ARP poisoning, and domain hijacking do not match the specific symptom of multiple clients resolving banking domains to an unknown server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Evil twin

    Why it's wrong here

    An evil twin is a rogue wireless access point that mimics a legitimate SSID to intercept traffic. The scenario describes wired workstations on a subnet with correct DHCP and DNS settings, not a wireless association issue. An evil twin would not change DNS resolution for multiple wired clients unless combined with other attacks, making it less likely here.

  • ✗

    Domain hijacking

    Why it's wrong here

    Domain hijacking involves an attacker taking control of a domain's registration, changing its name servers or ownership. That would affect the domain globally, not just several workstations on one subnet. The localized nature of the incorrect resolution points to a local DNS cache poisoning rather than a registry-level domain takeover.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning maps an attacker's MAC address to a legitimate IP, enabling man-in-the-middle attacks on the local subnet. It can redirect traffic, but the symptom here is incorrect DNS resolution of specific domains, not general traffic interception. ARP poisoning would not by itself cause banking domains to resolve to an unknown server without also manipulating DNS.

  • ✓

    DNS poisoning

    Why this is correct

    DNS poisoning corrupts the DNS resolver's cache so that legitimate domain names resolve to attacker-controlled IP addresses. Since DHCP and Group Policy are unchanged, the redirection of banking domains to an unknown server strongly indicates that the DNS cache has been poisoned. This allows the attacker to redirect users to malicious sites without altering client configuration.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.