Question 2 of 464
N10-009 Network Security Practice Question
Which attack technique involves an attacker intercepting and potentially modifying the communication between two parties without their knowledge?
⚠ Common exam trap
Watch out — candidates often confuse a replay attack with a MITM attack because both involve capturing traffic, but a replay attack only retransmits captured data without real-time interception or modification of the ongoing session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Man-in-the-middle
A man-in-the-middle (MITM) attack is correct because it specifically involves an attacker secretly intercepting and potentially altering communications between two parties who believe they are directly communicating with each other. This is achieved by the attacker inserting themselves into the communication path, often by ARP spoofing, DNS spoofing, or rogue access points, allowing them to capture, decrypt, or modify packets in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Man-in-the-middle
Why this is correct
A Man-in-the-Middle (MitM) attack positions the attacker transparently between two communicating parties, allowing them to intercept, read, and potentially modify all data exchanged without either party being aware. The attacker effectively spoofs the identities of both endpoints, making each believe they are communicating directly with the other. This enables real-time manipulation of the communication stream, making it a highly effective method for data theft or session hijacking.
- ✗
Replay attack
Why it's wrong here
A replay attack involves an attacker capturing a legitimate data transmission, such as authentication credentials or session tokens, and then retransmitting it later to impersonate the original sender or gain unauthorized access. While it involves capturing data, the attacker typically does not intercept and modify the *ongoing* communication in real-time. Instead, they "replay" previously valid data to achieve a desired outcome, often bypassing authentication mechanisms that lack proper timestamping or nonce usage.
When this WOULD be correct
A replay attack would be correct for a question like: 'Which attack involves capturing network traffic and retransmitting it to impersonate a legitimate user or gain unauthorized access?'
- ✗
Smurf attack
Why it's wrong here
A Smurf attack is a Distributed Denial-of-Service (DDoS) technique that exploits ICMP echo requests and IP broadcast addresses to overwhelm a target system. The attacker sends ICMP echo requests with the victim's spoofed IP address as the source to an IP broadcast address of an intermediary network. All hosts on that network then reply to the victim, flooding it with a massive volume of ICMP echo replies, leading to service disruption rather than data interception.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering attack that relies on deception to trick individuals into revealing sensitive information or installing malicious software. Attackers typically send fraudulent emails, messages, or create fake websites impersonating legitimate entities to solicit credentials, financial data, or other personal details directly from the user. This method manipulates human trust and vigilance, operating at the application layer and user interaction level, rather than directly intercepting network traffic.
When this WOULD be correct
A question asking 'Which attack involves sending fraudulent emails to trick users into revealing credentials?' would have phishing as the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Man-in-the-middleCorrect answer▾
Why this is correct
A Man-in-the-Middle (MitM) attack positions the attacker transparently between two communicating parties, allowing them to intercept, read, and potentially modify all data exchanged without either party being aware. The attacker effectively spoofs the identities of both endpoints, making each believe they are communicating directly with the other. This enables real-time manipulation of the communication stream, making it a highly effective method for data theft or session hijacking.
✗Replay attackWrong answer — click to see why▾
Why this is wrong here
A replay attack involves capturing and retransmitting valid data, but it does not inherently intercept or modify live communication between two parties; the attacker typically does not position themselves in the middle of the ongoing session.
★ When this WOULD be the correct answer
A replay attack would be correct for a question like: 'Which attack involves capturing network traffic and retransmitting it to impersonate a legitimate user or gain unauthorized access?'
Why candidates choose this
Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting data, but they overlook that replay attacks focus on reuse rather than real-time modification or interception of the communication channel.
✗PhishingWrong answer — click to see why▾
Why this is wrong here
Phishing is a social engineering attack that tricks users into revealing sensitive information, not an attack that intercepts or modifies communication between two parties.
★ When this WOULD be the correct answer
A question asking 'Which attack involves sending fraudulent emails to trick users into revealing credentials?' would have phishing as the correct answer.
Why candidates choose this
Candidates may confuse phishing with man-in-the-middle because both involve deception, but phishing targets the user directly rather than the communication channel.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.