ISC2 CC Network Security Practice Question
A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?
⚠ Common exam trap
The trap here is attributing any DNS anomaly to domain hijacking, when a resolver-scoped wrong answer more strongly indicates cache poisoning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS cache poisoning
When a workstation uses the corporate resolver and suddenly receives an attacker-controlled IP for a legitimate banking domain, the most likely cause is that the resolver's cache has been poisoned with a forged record. DNS cache poisoning redirects users to malicious destinations without changing endpoint configuration. Tunneling, domain hijacking, and amplification do not match the observed symptom of a wrong but locally scoped resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling encodes data within DNS queries and responses to exfiltrate information or establish command-and-control channels. It typically generates unusual query patterns, long subdomains, or high volumes of TXT records, but it does not normally change the resolved IP address of a legitimate banking domain to an unrelated external host. The observed behavior points to record manipulation rather than covert data transfer.
- ✗
Domain hijacking
Why it's wrong here
Domain hijacking involves an attacker taking control of a domain's registration, often through compromised registrar credentials, and changing its authoritative name servers. That would affect resolution globally and would likely be noticed by the domain owner and many users. Here the issue appears limited to the corporate resolver's cache, so hijacking at the registrar level is less likely than cache poisoning.
- ✗
DNS amplification
Why it's wrong here
DNS amplification is a denial-of-service technique that abuses open resolvers to send large responses to a spoofed victim address. It floods a target with traffic and does not alter the IP address a workstation receives for a banking domain. The scenario describes incorrect resolution rather than a volumetric attack, so amplification does not fit the evidence.
- ✓
DNS cache poisoning
Why this is correct
DNS cache poisoning inserts false records into a resolver's cache so that legitimate domain names resolve to attacker-controlled addresses. Since the workstation uses the corporate resolver and no local configuration changed, a poisoned cache on that resolver would explain the incorrect answer. This enables redirection to malicious sites and is a classic man-in-the-middle enabler.
Visual reference
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.