Courseiva
Network SecurityhardMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

An attacker intercepts communication between two parties and is able to modify the data in transit without either party's knowledge. Which type of attack is this?

⚠ Common exam trap

The N10-009 exam often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP spoofing, DNS poisoning), so candidates mistakenly select the technique rather than the overarching attack described in the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Man-in-the-middle

A man-in-the-middle (MITM) attack occurs when an adversary secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker can modify data in transit without either party's knowledge by placing themselves in the logical or physical path of the data flow, often by exploiting weaknesses in authentication or encryption. This matches the scenario described, where the attacker both intercepts and modifies the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Man-in-the-middle

    Why this is correct

    A Man-in-the-Middle (MITM) attack involves an unauthorized third party secretly relaying and potentially altering the communication between two parties who believe they are directly communicating. The attacker positions themselves logically between the endpoints, intercepting all traffic, reading its contents, and then forwarding it, often after modification, to the intended recipient. This allows the attacker to eavesdrop, inject false information, or manipulate data in real-time without detection by the legitimate participants, precisely matching the scenario described.

  • ARP spoofing

    Why it's wrong here

    ARP spoofing is a Layer 2 attack that involves sending forged Address Resolution Protocol (ARP) messages over a local area network. The attacker's goal is to associate their own MAC address with the IP address of another host, such as the default gateway or another victim, on the network. This redirects traffic intended for the legitimate host through the attacker's machine, serving as a common prerequisite for a Man-in-the-Middle attack, but it is primarily a traffic redirection mechanism, not the act of data modification itself.

    When this WOULD be correct

    A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway, causing traffic to be redirected through the attacker's machine. Which type of attack is this?' would make ARP spoofing the correct answer.

  • DNS poisoning

    Why it's wrong here

    DNS poisoning, also known as DNS cache poisoning, is an attack where corrupted Domain Name System (DNS) data is introduced into a DNS resolver's cache. This causes the resolver to return an incorrect IP address for a legitimate domain name, effectively redirecting users to a malicious website controlled by the attacker. While it redirects traffic, DNS poisoning itself does not involve the real-time interception and modification of data *during* an established communication session, but rather manipulates where that session is initially directed.

    When this WOULD be correct

    A question describing an attack where users are redirected to a fake website that mimics a legitimate one, and the attacker captures credentials or serves malware, would make DNS poisoning the correct answer.

  • Replay attack

    Why it's wrong here

    A replay attack involves an attacker intercepting a legitimate data transmission, such as authentication credentials or a transaction request, and then retransmitting it later to impersonate the original sender or repeat an action. The attacker does not necessarily modify the captured data but simply reuses it to achieve an unauthorized outcome. This differs from a Man-in-the-Middle attack, which focuses on real-time interception and modification of an ongoing communication stream rather than merely re-sending previously captured packets.

    When this WOULD be correct

    A replay attack would be correct if the question described an attacker capturing authentication tokens or session data and reusing them to impersonate a user, without any modification of the data.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Man-in-the-middleCorrect answer

Why this is correct

A Man-in-the-Middle (MITM) attack involves an unauthorized third party secretly relaying and potentially altering the communication between two parties who believe they are directly communicating. The attacker positions themselves logically between the endpoints, intercepting all traffic, reading its contents, and then forwarding it, often after modification, to the intended recipient. This allows the attacker to eavesdrop, inject false information, or manipulate data in real-time without detection by the legitimate participants, precisely matching the scenario described.

ARP spoofingWrong answer — click to see why

Why this is wrong here

ARP spoofing is a technique used to associate an attacker's MAC address with the IP address of a legitimate device, enabling interception of traffic, but it does not inherently involve modifying data in transit. The question specifies modification of data, which is a key characteristic of a man-in-the-middle attack, not ARP spoofing alone.

★ When this WOULD be the correct answer

A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway, causing traffic to be redirected through the attacker's machine. Which type of attack is this?' would make ARP spoofing the correct answer.

Why candidates choose this

Candidates may confuse ARP spoofing with man-in-the-middle because ARP spoofing is often used as a precursor to a man-in-the-middle attack, leading them to incorrectly select it as the primary attack type when the question focuses on data modification.

DNS poisoningWrong answer — click to see why

Why this is wrong here

DNS poisoning involves corrupting DNS resolver caches to redirect traffic to malicious sites, but it does not inherently allow real-time modification of data in transit between two parties.

★ When this WOULD be the correct answer

A question describing an attack where users are redirected to a fake website that mimics a legitimate one, and the attacker captures credentials or serves malware, would make DNS poisoning the correct answer.

Why candidates choose this

Candidates may confuse DNS poisoning with man-in-the-middle because both can intercept traffic, but they overlook that DNS poisoning redirects traffic rather than modifying data in an existing session.

Replay attackWrong answer — click to see why

Why this is wrong here

A replay attack involves capturing and retransmitting valid data, but it does not allow the attacker to modify data in transit without detection. The question specifies modification, which is a key feature of man-in-the-middle attacks.

★ When this WOULD be the correct answer

A replay attack would be correct if the question described an attacker capturing authentication tokens or session data and reusing them to impersonate a user, without any modification of the data.

Why candidates choose this

Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting communications, but they overlook that replay attacks do not involve altering the data.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.