Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

⚠ Common exam trap

Many candidates confuse DoS attacks (SYN flood, DNS amplification, ICMP flood) with MITM attacks; candidates may select any flooding technique thinking it involves interception, but only ARP poisoning and rogue APs directly enable man-in-the-middle positioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP poisoning

ARP poisoning (A) is a classic MITM technique: the attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway (or another host), causing victim traffic to flow through the attacker, who can then intercept or modify it. Setting up a rogue Wi-Fi access point (D) is also a common MITM method, often called an evil twin attack, where victims connect to the attacker-controlled AP and all their traffic is relayed or captured by the attacker. The other options are denial-of-service or amplification attacks rather than interception techniques: a SYN flood (B) exhausts TCP connection state to deny service, DNS amplification (C) abuses open DNS resolvers to flood a target with large responses, and an ICMP flood (E) overwhelms a target with ping traffic — none of these position the attacker to intercept and relay traffic between two parties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ARP poisoning

    Why this is correct

    ARP poisoning sends forged ARP replies that bind the attacker's MAC address to a legitimate IP, so traffic between victim and gateway flows through the attacker. This enables interception and modification on the local subnet, a classic MITM technique.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood exhausts a server's half-open connection table, denying service rather than inserting an attacker into an existing session. It is tempting because TCP manipulation underlies MITM techniques such as session hijacking, yet SYN flooding's mechanism is resource exhaustion, making it the answer for a DoS question, not MITM.

  • ✗

    DNS amplification

    Why it's wrong here

    DNS amplification is a reflection-based volumetric DoS attack that spoofs a victim's address to flood it with large DNS responses; it never positions an attacker between two communicating parties. It is tempting because DNS features in MITM via spoofing or cache poisoning, but amplification's purpose is bandwidth exhaustion, not interception.

  • ✓

    Setting up a rogue Wi-Fi access point

    Why this is correct

    A rogue access point impersonates a legitimate wireless network, forcing clients to associate with the attacker's hardware. Traffic then routes through the adversary, enabling interception and modification. This satisfies the man-in-the-middle constraint by inserting the attacker transparently between victim and destination on the wireless link itself.

  • ✗

    ICMP flood

    Why it's wrong here

    An ICMP flood is a denial-of-service technique that saturates a target with echo requests, exhausting bandwidth; it intercepts nothing and relays no traffic. It is tempting because ICMP is used for reconnaissance and tunnelling, so it appears in attack discussions, but it would be the answer for a volumetric DoS question rather than MITM.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.