Courseiva
Network SecuritymediumMatchingObjective-mapped

N10-009 Network Security Practice Question

Match each network attack to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Attacker sends fake ARP messages to associate their MAC with another IP

Corrupts DNS cache to redirect traffic to malicious sites

Overwhelms a target with traffic from multiple sources

Attacker intercepts communication between two parties

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Distributed Denial-of-Service (DDoS): Overwhelms a network or server with a flood of traffic from multiple sources

DDoS attacks flood systems with traffic, MitM attacks intercept communications, phishing tricks users into revealing info, and ransomware encrypts files for ransom.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Distributed Denial-of-Service (DDoS): Overwhelms a network or server with a flood of traffic from multiple sources

    Why this is correct

    A Distributed Denial-of-Service (DDoS) attack aims to make a network service or resource unavailable to its legitimate users by overwhelming it with a massive flood of malicious traffic. This traffic originates from numerous compromised systems, often forming a botnet, which collectively saturate the target's bandwidth or exhaust its processing capabilities. The sheer volume of requests prevents the target system from responding to legitimate requests, leading to service disruption.

  • Man-in-the-Middle (MitM): Intercepts and potentially alters communication between two parties without their knowledge

    Why this is correct

    A Man-in-the-Middle (MitM) attack positions the attacker covertly between two communicating parties, allowing them to intercept, read, and potentially modify the data exchanged between them. The legitimate parties remain unaware that their communication is being compromised, believing they are communicating directly. This type of attack often leverages techniques like ARP spoofing or DNS spoofing to redirect traffic through the attacker's system, compromising both confidentiality and integrity.

  • Phishing: Sends fraudulent emails or messages tricking users into revealing sensitive information

    Why this is correct

    Phishing is a social engineering attack where an attacker sends deceptive communications, typically emails or text messages, impersonating a trustworthy entity to trick individuals. The objective is to manipulate recipients into divulging sensitive personal information, such as login credentials, financial details, or other confidential data. These fraudulent messages often contain malicious links or attachments designed to compromise the user's system or steal information directly.

  • Ransomware: Malware that encrypts files and demands payment for decryption

    Why this is correct

    Ransomware is a malicious software program that, once executed on a system, encrypts the user's files or locks down the entire operating system, rendering data inaccessible. The attacker then demands a monetary payment, typically in cryptocurrency, in exchange for a decryption key or tool to restore access to the compromised data. This attack directly impacts data availability and can cause significant operational disruption for individuals and organizations.

  • Distributed Denial-of-Service (DDoS): Intercepts communication between two parties

    Why it's wrong here

    This description is incorrect for a Distributed Denial-of-Service (DDoS) attack. DDoS attacks primarily aim to disrupt the availability of a service by overwhelming it with traffic, not to secretly intercept or read ongoing communications. The act of intercepting communication between two parties without their knowledge is characteristic of a Man-in-the-Middle (MitM) attack, which focuses on compromising confidentiality and integrity rather than availability.

  • Phishing: Malware that encrypts data for ransom

    Why it's wrong here

    This description is incorrect for phishing. Phishing is a social engineering technique that relies on deception to trick users into voluntarily providing information or performing actions, such as clicking a malicious link. The act of encrypting data and demanding a ransom for its decryption is the defining characteristic of ransomware, which is a type of malicious software, fundamentally different from the human-centric deception of phishing.

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.