Question 139 of 464
N10-009 Network Security Practice Question
A security administrator discovers that an attacker has intercepted data between two legitimate hosts by redirecting traffic through a rogue device. Which type of attack is this?
⚠ Common exam trap
CompTIA often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP poisoning), leading candidates to choose the method rather than the broader category.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Man-in-the-middle
This is a classic man-in-the-middle (MITM) attack, where the attacker intercepts and potentially alters communication between two legitimate hosts by inserting a rogue device into the data path. The key characteristic is the redirection of traffic through the attacker's device, which allows them to capture, inspect, or modify packets in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning, or ARP spoofing, is a technique where an attacker sends falsified ARP messages over a local area network. This associates the attacker's MAC address with the IP address of another host, such as the default gateway, on the network, thereby rerouting traffic through the attacker. While ARP poisoning is a common method used to redirect traffic and establish a Man-in-the-Middle position, it is the underlying mechanism for achieving interception, not the overarching attack type of intercepting data between two legitimate hosts.
When this WOULD be correct
A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway. Which type of attack is this?' would make ARP poisoning the correct answer.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning involves injecting falsified DNS records into a DNS resolver's cache or a DNS server itself, causing it to return an incorrect IP address for a legitimate domain name. This redirects users attempting to access a specific website or service to an attacker-controlled malicious site instead of the intended destination. While it can lead to a user connecting to a malicious host, it primarily manipulates the initial name resolution process rather than directly intercepting an ongoing data stream between two already-connected legitimate hosts.
When this WOULD be correct
A question describing an attacker modifying DNS cache entries to redirect users to a fake login page for credential harvesting would make DNS poisoning the correct answer.
- ✓
Man-in-the-middle
Why this is correct
A Man-in-the-Middle (MITM) attack occurs when an attacker secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the data path, effectively becoming an intermediary that can eavesdrop on, capture, or even manipulate the data in real-time without either legitimate party being aware of the compromise. This direct interception of data between two hosts perfectly matches the scenario described.
- ✗
Replay attack
Why it's wrong here
A replay attack involves an attacker capturing a legitimate data transmission, such as authentication credentials or a transaction request, and then retransmitting it later to impersonate a legitimate user or trigger a repeated action. The attacker does not actively intercept or modify the data in real-time during the original communication. Instead, they passively record the traffic and then 'replay' the captured packets at a later time to achieve their malicious objective, which is distinct from real-time interception.
When this WOULD be correct
An exam question might describe an attacker capturing a valid authentication packet and retransmitting it later to gain unauthorized access, without any mention of traffic redirection or a rogue device. In that scenario, replay attack would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Man-in-the-middleCorrect answer▾
Why this is correct
A Man-in-the-Middle (MITM) attack occurs when an attacker secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker positions themselves in the data path, effectively becoming an intermediary that can eavesdrop on, capture, or even manipulate the data in real-time without either legitimate party being aware of the compromise. This direct interception of data between two hosts perfectly matches the scenario described.
✗ARP poisoningWrong answer — click to see why▾
Why this is wrong here
ARP poisoning is a technique used to associate an attacker's MAC address with the IP address of a legitimate host, enabling traffic interception. However, the question describes redirecting traffic through a rogue device, which is the definition of a man-in-the-middle attack, not specifically ARP poisoning.
★ When this WOULD be the correct answer
A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway. Which type of attack is this?' would make ARP poisoning the correct answer.
Why candidates choose this
Candidates may confuse ARP poisoning with man-in-the-middle because ARP poisoning is a common method used to achieve a man-in-the-middle position, but the question describes the broader attack type, not the specific technique.
✗DNS poisoningWrong answer — click to see why▾
Why this is wrong here
DNS poisoning involves corrupting DNS records to redirect traffic to malicious sites, not intercepting traffic between two hosts via a rogue device.
★ When this WOULD be the correct answer
A question describing an attacker modifying DNS cache entries to redirect users to a fake login page for credential harvesting would make DNS poisoning the correct answer.
Why candidates choose this
Candidates may confuse DNS poisoning with ARP poisoning or think any redirection attack is DNS-related, overlooking the specific mechanism of traffic interception via a rogue device.
✗Replay attackWrong answer — click to see why▾
Why this is wrong here
A replay attack involves capturing and retransmitting valid data to produce an unauthorized effect, but it does not inherently involve redirecting traffic through a rogue device; the question describes traffic redirection, which is characteristic of a man-in-the-middle attack.
★ When this WOULD be the correct answer
An exam question might describe an attacker capturing a valid authentication packet and retransmitting it later to gain unauthorized access, without any mention of traffic redirection or a rogue device. In that scenario, replay attack would be the correct answer.
Why candidates choose this
Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting data, but replay focuses on reusing captured data rather than actively redirecting and modifying traffic in real time.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 30, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.