Courseiva
Question 2 of 464
Network SecurityeasyMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

Which attack technique involves an attacker intercepting and potentially modifying the communication between two parties without their knowledge?

⚠ Common exam trap

Watch out — candidates often confuse a replay attack with a MITM attack because both involve capturing traffic, but a replay attack only retransmits captured data without real-time interception or modification of the ongoing session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Man-in-the-middle

A man-in-the-middle (MITM) attack is correct because it specifically involves an attacker secretly intercepting and potentially altering communications between two parties who believe they are directly communicating with each other. This is achieved by the attacker inserting themselves into the communication path, often by ARP spoofing, DNS spoofing, or rogue access points, allowing them to capture, decrypt, or modify packets in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Man-in-the-middle

    Why this is correct

    A Man-in-the-Middle (MitM) attack positions the attacker transparently between two communicating parties, allowing them to intercept, read, and potentially modify all data exchanged without either party being aware. The attacker effectively spoofs the identities of both endpoints, making each believe they are communicating directly with the other. This enables real-time manipulation of the communication stream, making it a highly effective method for data theft or session hijacking.

  • Replay attack

    Why it's wrong here

    A replay attack involves an attacker capturing a legitimate data transmission, such as authentication credentials or session tokens, and then retransmitting it later to impersonate the original sender or gain unauthorized access. While it involves capturing data, the attacker typically does not intercept and modify the *ongoing* communication in real-time. Instead, they "replay" previously valid data to achieve a desired outcome, often bypassing authentication mechanisms that lack proper timestamping or nonce usage.

    When this WOULD be correct

    A replay attack would be correct for a question like: 'Which attack involves capturing network traffic and retransmitting it to impersonate a legitimate user or gain unauthorized access?'

  • Smurf attack

    Why it's wrong here

    A Smurf attack is a Distributed Denial-of-Service (DDoS) technique that exploits ICMP echo requests and IP broadcast addresses to overwhelm a target system. The attacker sends ICMP echo requests with the victim's spoofed IP address as the source to an IP broadcast address of an intermediary network. All hosts on that network then reply to the victim, flooding it with a massive volume of ICMP echo replies, leading to service disruption rather than data interception.

  • Phishing

    Why it's wrong here

    Phishing is a social engineering attack that relies on deception to trick individuals into revealing sensitive information or installing malicious software. Attackers typically send fraudulent emails, messages, or create fake websites impersonating legitimate entities to solicit credentials, financial data, or other personal details directly from the user. This method manipulates human trust and vigilance, operating at the application layer and user interaction level, rather than directly intercepting network traffic.

    When this WOULD be correct

    A question asking 'Which attack involves sending fraudulent emails to trick users into revealing credentials?' would have phishing as the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Man-in-the-middleCorrect answer

Why this is correct

A Man-in-the-Middle (MitM) attack positions the attacker transparently between two communicating parties, allowing them to intercept, read, and potentially modify all data exchanged without either party being aware. The attacker effectively spoofs the identities of both endpoints, making each believe they are communicating directly with the other. This enables real-time manipulation of the communication stream, making it a highly effective method for data theft or session hijacking.

Replay attackWrong answer — click to see why

Why this is wrong here

A replay attack involves capturing and retransmitting valid data, but it does not inherently intercept or modify live communication between two parties; the attacker typically does not position themselves in the middle of the ongoing session.

★ When this WOULD be the correct answer

A replay attack would be correct for a question like: 'Which attack involves capturing network traffic and retransmitting it to impersonate a legitimate user or gain unauthorized access?'

Why candidates choose this

Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting data, but they overlook that replay attacks focus on reuse rather than real-time modification or interception of the communication channel.

PhishingWrong answer — click to see why

Why this is wrong here

Phishing is a social engineering attack that tricks users into revealing sensitive information, not an attack that intercepts or modifies communication between two parties.

★ When this WOULD be the correct answer

A question asking 'Which attack involves sending fraudulent emails to trick users into revealing credentials?' would have phishing as the correct answer.

Why candidates choose this

Candidates may confuse phishing with man-in-the-middle because both involve deception, but phishing targets the user directly rather than the communication channel.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.