Courseiva
Question 139 of 464
Network SecuritymediumMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A security administrator discovers that an attacker has intercepted data between two legitimate hosts by redirecting traffic through a rogue device. Which type of attack is this?

⚠ Common exam trap

CompTIA often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP poisoning), leading candidates to choose the method rather than the broader category.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Man-in-the-middle

This is a classic man-in-the-middle (MITM) attack, where the attacker intercepts and potentially alters communication between two legitimate hosts by inserting a rogue device into the data path. The key characteristic is the redirection of traffic through the attacker's device, which allows them to capture, inspect, or modify packets in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ARP poisoning

    Why it's wrong here

    ARP poisoning, or ARP spoofing, is a technique where an attacker sends falsified ARP messages over a local area network. This associates the attacker's MAC address with the IP address of another host, such as the default gateway, on the network, thereby rerouting traffic through the attacker. While ARP poisoning is a common method used to redirect traffic and establish a Man-in-the-Middle position, it is the underlying mechanism for achieving interception, not the overarching attack type of intercepting data between two legitimate hosts.

    When this WOULD be correct

    A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway. Which type of attack is this?' would make ARP poisoning the correct answer.

  • DNS poisoning

    Why it's wrong here

    DNS poisoning involves injecting falsified DNS records into a DNS resolver's cache or a DNS server itself, causing it to return an incorrect IP address for a legitimate domain name. This redirects users attempting to access a specific website or service to an attacker-controlled malicious site instead of the intended destination. While it can lead to a user connecting to a malicious host, it primarily manipulates the initial name resolution process rather than directly intercepting an ongoing data stream between two already-connected legitimate hosts.

    When this WOULD be correct

    A question describing an attacker modifying DNS cache entries to redirect users to a fake login page for credential harvesting would make DNS poisoning the correct answer.

  • Man-in-the-middle

    Why this is correct

    A Man-in-the-Middle (MITM) attack occurs when an attacker secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the data path, effectively becoming an intermediary that can eavesdrop on, capture, or even manipulate the data in real-time without either legitimate party being aware of the compromise. This direct interception of data between two hosts perfectly matches the scenario described.

  • Replay attack

    Why it's wrong here

    A replay attack involves an attacker capturing a legitimate data transmission, such as authentication credentials or a transaction request, and then retransmitting it later to impersonate a legitimate user or trigger a repeated action. The attacker does not actively intercept or modify the data in real-time during the original communication. Instead, they passively record the traffic and then 'replay' the captured packets at a later time to achieve their malicious objective, which is distinct from real-time interception.

    When this WOULD be correct

    An exam question might describe an attacker capturing a valid authentication packet and retransmitting it later to gain unauthorized access, without any mention of traffic redirection or a rogue device. In that scenario, replay attack would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Man-in-the-middleCorrect answer

Why this is correct

A Man-in-the-Middle (MITM) attack occurs when an attacker secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the data path, effectively becoming an intermediary that can eavesdrop on, capture, or even manipulate the data in real-time without either legitimate party being aware of the compromise. This direct interception of data between two hosts perfectly matches the scenario described.

ARP poisoningWrong answer — click to see why

Why this is wrong here

ARP poisoning is a technique used to associate an attacker's MAC address with the IP address of a legitimate host, enabling traffic interception. However, the question describes redirecting traffic through a rogue device, which is the definition of a man-in-the-middle attack, not specifically ARP poisoning.

★ When this WOULD be the correct answer

A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway. Which type of attack is this?' would make ARP poisoning the correct answer.

Why candidates choose this

Candidates may confuse ARP poisoning with man-in-the-middle because ARP poisoning is a common method used to achieve a man-in-the-middle position, but the question describes the broader attack type, not the specific technique.

DNS poisoningWrong answer — click to see why

Why this is wrong here

DNS poisoning involves corrupting DNS records to redirect traffic to malicious sites, not intercepting traffic between two hosts via a rogue device.

★ When this WOULD be the correct answer

A question describing an attacker modifying DNS cache entries to redirect users to a fake login page for credential harvesting would make DNS poisoning the correct answer.

Why candidates choose this

Candidates may confuse DNS poisoning with ARP poisoning or think any redirection attack is DNS-related, overlooking the specific mechanism of traffic interception via a rogue device.

Replay attackWrong answer — click to see why

Why this is wrong here

A replay attack involves capturing and retransmitting valid data to produce an unauthorized effect, but it does not inherently involve redirecting traffic through a rogue device; the question describes traffic redirection, which is characteristic of a man-in-the-middle attack.

★ When this WOULD be the correct answer

An exam question might describe an attacker capturing a valid authentication packet and retransmitting it later to gain unauthorized access, without any mention of traffic redirection or a rogue device. In that scenario, replay attack would be the correct answer.

Why candidates choose this

Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting data, but replay focuses on reusing captured data rather than actively redirecting and modifying traffic in real time.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.