Courseiva
Network SecuritymediumMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A security analyst notices that the network has been flooded with packets that have the same source IP address as the company's internal DNS server. This is likely an example of which type of attack?

⚠ Common exam trap

CompTIA often tests the distinction between IP spoofing and Smurf attacks, where candidates mistakenly choose Smurf because both involve spoofed source addresses, but Smurf specifically requires ICMP and broadcast amplification, not arbitrary packet flooding with a DNS server's IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IP spoofing

IP spoofing is the correct answer because the attacker is forging the source IP address of packets to impersonate the company's internal DNS server. By flooding the network with packets that appear to originate from a trusted internal server, the attacker can bypass security controls, launch reflection attacks, or cause denial of service. This directly matches the scenario where the source IP is falsified to match a legitimate internal host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smurf attack

    Why it's wrong here

    A Smurf attack is a specific type of distributed denial-of-service (DDoS) attack that leverages ICMP echo requests and IP spoofing for amplification. An attacker sends ICMP echo requests to a network's broadcast address, spoofing the source IP address to be that of the victim. All hosts on the broadcast network then reply to the victim's spoofed IP, creating a massive flood of ICMP echo replies that overwhelm the target, a detail not explicitly mentioned in the general 'network has been flooded' scenario.

    When this WOULD be correct

    A Smurf attack would be correct if the question described a network flooded with ICMP echo requests sent to a broadcast address, and the source IP was spoofed to be the victim's IP, causing all hosts on the network to reply to the victim.

  • IP spoofing

    Why this is correct

    IP spoofing is a technique where an attacker crafts IP packets with a forged source IP address, making them appear to originate from a different, often trusted, host. In the context of a network flood, this allows an attacker to send a massive volume of traffic without revealing their true identity or location. This obfuscation complicates traceback efforts and makes it harder for network defenders to block the malicious source effectively, contributing directly to the observed network congestion.

  • Man-in-the-middle

    Why it's wrong here

    A man-in-the-middle (MITM) attack occurs when an attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the communication path to intercept, read, or modify data without detection. This attack focuses on covert interception and manipulation of data streams, which is fundamentally different from a network flood, where the objective is to overwhelm network resources with an excessive volume of traffic.

    When this WOULD be correct

    A man-in-the-middle attack would be correct if the question described an attacker intercepting and modifying traffic between a client and the DNS server, such as by ARP spoofing or using a rogue access point, to eavesdrop or inject false responses.

  • ARP poisoning

    Why it's wrong here

    ARP poisoning involves sending forged Address Resolution Protocol (ARP) replies to a local area network, associating an attacker's MAC address with the IP address of another host, such as a default gateway. This manipulation redirects traffic intended for the legitimate host through the attacker's machine, enabling interception or modification. While it involves 'spoofed' ARP packets, its primary goal is traffic redirection for eavesdropping or alteration, not to overwhelm the network with a flood of general data packets.

    When this WOULD be correct

    An exam question describing an attacker intercepting traffic by sending forged ARP replies to associate their MAC address with the default gateway's IP address, causing traffic to be redirected through the attacker's machine.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

IP spoofingCorrect answer

Why this is correct

IP spoofing is a technique where an attacker crafts IP packets with a forged source IP address, making them appear to originate from a different, often trusted, host. In the context of a network flood, this allows an attacker to send a massive volume of traffic without revealing their true identity or location. This obfuscation complicates traceback efforts and makes it harder for network defenders to block the malicious source effectively, contributing directly to the observed network congestion.

Smurf attackWrong answer — click to see why

Why this is wrong here

A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim. This question describes packets with the same source IP as the internal DNS server, which is IP spoofing, not a Smurf attack.

★ When this WOULD be the correct answer

A Smurf attack would be correct if the question described a network flooded with ICMP echo requests sent to a broadcast address, and the source IP was spoofed to be the victim's IP, causing all hosts on the network to reply to the victim.

Why candidates choose this

Candidates may confuse IP spoofing with Smurf attacks because both involve spoofed source addresses, and Smurf attacks are a classic example of a DDoS using spoofing, leading them to select Smurf when the key detail is the spoofed source IP of the DNS server.

Man-in-the-middleWrong answer — click to see why

Why this is wrong here

A man-in-the-middle attack involves intercepting and potentially altering communications between two parties, but the question describes a flood of packets with a spoofed source IP, which is characteristic of IP spoofing, not MITM.

★ When this WOULD be the correct answer

A man-in-the-middle attack would be correct if the question described an attacker intercepting and modifying traffic between a client and the DNS server, such as by ARP spoofing or using a rogue access point, to eavesdrop or inject false responses.

Why candidates choose this

Candidates may confuse IP spoofing with MITM because both involve deceptive addressing, but MITM focuses on interception and relay, whereas IP spoofing is about falsifying the source address in packets.

ARP poisoningWrong answer — click to see why

Why this is wrong here

ARP poisoning involves manipulating ARP tables to associate a malicious MAC address with a legitimate IP address, but the question describes packets with a spoofed source IP address, not ARP table manipulation.

★ When this WOULD be the correct answer

An exam question describing an attacker intercepting traffic by sending forged ARP replies to associate their MAC address with the default gateway's IP address, causing traffic to be redirected through the attacker's machine.

Why candidates choose this

Candidates may confuse IP spoofing with ARP poisoning because both involve impersonation at different layers, and ARP poisoning is a common attack type that can involve spoofed IP addresses in some contexts.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.