N10-009 Network Security Practice Question
A security analyst notices that the network has been flooded with packets that have the same source IP address as the company's internal DNS server. This is likely an example of which type of attack?
⚠ Common exam trap
CompTIA often tests the distinction between IP spoofing and Smurf attacks, where candidates mistakenly choose Smurf because both involve spoofed source addresses, but Smurf specifically requires ICMP and broadcast amplification, not arbitrary packet flooding with a DNS server's IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP spoofing
IP spoofing is the correct answer because the attacker is forging the source IP address of packets to impersonate the company's internal DNS server. By flooding the network with packets that appear to originate from a trusted internal server, the attacker can bypass security controls, launch reflection attacks, or cause denial of service. This directly matches the scenario where the source IP is falsified to match a legitimate internal host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smurf attack
Why it's wrong here
A Smurf attack is a specific type of distributed denial-of-service (DDoS) attack that leverages ICMP echo requests and IP spoofing for amplification. An attacker sends ICMP echo requests to a network's broadcast address, spoofing the source IP address to be that of the victim. All hosts on the broadcast network then reply to the victim's spoofed IP, creating a massive flood of ICMP echo replies that overwhelm the target, a detail not explicitly mentioned in the general 'network has been flooded' scenario.
When this WOULD be correct
A Smurf attack would be correct if the question described a network flooded with ICMP echo requests sent to a broadcast address, and the source IP was spoofed to be the victim's IP, causing all hosts on the network to reply to the victim.
- ✓
IP spoofing
Why this is correct
IP spoofing is a technique where an attacker crafts IP packets with a forged source IP address, making them appear to originate from a different, often trusted, host. In the context of a network flood, this allows an attacker to send a massive volume of traffic without revealing their true identity or location. This obfuscation complicates traceback efforts and makes it harder for network defenders to block the malicious source effectively, contributing directly to the observed network congestion.
- ✗
Man-in-the-middle
Why it's wrong here
A man-in-the-middle (MITM) attack occurs when an attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the communication path to intercept, read, or modify data without detection. This attack focuses on covert interception and manipulation of data streams, which is fundamentally different from a network flood, where the objective is to overwhelm network resources with an excessive volume of traffic.
When this WOULD be correct
A man-in-the-middle attack would be correct if the question described an attacker intercepting and modifying traffic between a client and the DNS server, such as by ARP spoofing or using a rogue access point, to eavesdrop or inject false responses.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning involves sending forged Address Resolution Protocol (ARP) replies to a local area network, associating an attacker's MAC address with the IP address of another host, such as a default gateway. This manipulation redirects traffic intended for the legitimate host through the attacker's machine, enabling interception or modification. While it involves 'spoofed' ARP packets, its primary goal is traffic redirection for eavesdropping or alteration, not to overwhelm the network with a flood of general data packets.
When this WOULD be correct
An exam question describing an attacker intercepting traffic by sending forged ARP replies to associate their MAC address with the default gateway's IP address, causing traffic to be redirected through the attacker's machine.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓IP spoofingCorrect answer▾
Why this is correct
IP spoofing is a technique where an attacker crafts IP packets with a forged source IP address, making them appear to originate from a different, often trusted, host. In the context of a network flood, this allows an attacker to send a massive volume of traffic without revealing their true identity or location. This obfuscation complicates traceback efforts and makes it harder for network defenders to block the malicious source effectively, contributing directly to the observed network congestion.
✗Smurf attackWrong answer — click to see why▾
Why this is wrong here
A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim. This question describes packets with the same source IP as the internal DNS server, which is IP spoofing, not a Smurf attack.
★ When this WOULD be the correct answer
A Smurf attack would be correct if the question described a network flooded with ICMP echo requests sent to a broadcast address, and the source IP was spoofed to be the victim's IP, causing all hosts on the network to reply to the victim.
Why candidates choose this
Candidates may confuse IP spoofing with Smurf attacks because both involve spoofed source addresses, and Smurf attacks are a classic example of a DDoS using spoofing, leading them to select Smurf when the key detail is the spoofed source IP of the DNS server.
✗Man-in-the-middleWrong answer — click to see why▾
Why this is wrong here
A man-in-the-middle attack involves intercepting and potentially altering communications between two parties, but the question describes a flood of packets with a spoofed source IP, which is characteristic of IP spoofing, not MITM.
★ When this WOULD be the correct answer
A man-in-the-middle attack would be correct if the question described an attacker intercepting and modifying traffic between a client and the DNS server, such as by ARP spoofing or using a rogue access point, to eavesdrop or inject false responses.
Why candidates choose this
Candidates may confuse IP spoofing with MITM because both involve deceptive addressing, but MITM focuses on interception and relay, whereas IP spoofing is about falsifying the source address in packets.
✗ARP poisoningWrong answer — click to see why▾
Why this is wrong here
ARP poisoning involves manipulating ARP tables to associate a malicious MAC address with a legitimate IP address, but the question describes packets with a spoofed source IP address, not ARP table manipulation.
★ When this WOULD be the correct answer
An exam question describing an attacker intercepting traffic by sending forged ARP replies to associate their MAC address with the default gateway's IP address, causing traffic to be redirected through the attacker's machine.
Why candidates choose this
Candidates may confuse IP spoofing with ARP poisoning because both involve impersonation at different layers, and ARP poisoning is a common attack type that can involve spoofed IP addresses in some contexts.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.