ISC2 CC Network Security Practice Question
A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)
⚠ Common exam trap
Many candidates confuse DoS attacks (SYN flood, DNS amplification, ICMP flood) with MITM attacks; candidates may select any flooding technique thinking it involves interception, but only ARP poisoning and rogue APs directly enable man-in-the-middle positioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP poisoning
ARP poisoning (A) is a classic MITM technique: the attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway (or another host), causing victim traffic to flow through the attacker, who can then intercept or modify it. Setting up a rogue Wi-Fi access point (D) is also a common MITM method, often called an evil twin attack, where victims connect to the attacker-controlled AP and all their traffic is relayed or captured by the attacker. The other options are denial-of-service or amplification attacks rather than interception techniques: a SYN flood (B) exhausts TCP connection state to deny service, DNS amplification (C) abuses open DNS resolvers to flood a target with large responses, and an ICMP flood (E) overwhelms a target with ping traffic — none of these position the attacker to intercept and relay traffic between two parties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARP poisoning
Why this is correct
ARP poisoning sends forged ARP replies that bind the attacker's MAC address to a legitimate IP, so traffic between victim and gateway flows through the attacker. This enables interception and modification on the local subnet, a classic MITM technique.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts a server's half-open connection table, denying service rather than inserting an attacker into an existing session. It is tempting because TCP manipulation underlies MITM techniques such as session hijacking, yet SYN flooding's mechanism is resource exhaustion, making it the answer for a DoS question, not MITM.
- ✗
DNS amplification
Why it's wrong here
DNS amplification is a reflection-based volumetric DoS attack that spoofs a victim's address to flood it with large DNS responses; it never positions an attacker between two communicating parties. It is tempting because DNS features in MITM via spoofing or cache poisoning, but amplification's purpose is bandwidth exhaustion, not interception.
- ✓
Setting up a rogue Wi-Fi access point
Why this is correct
A rogue access point impersonates a legitimate wireless network, forcing clients to associate with the attacker's hardware. Traffic then routes through the adversary, enabling interception and modification. This satisfies the man-in-the-middle constraint by inserting the attacker transparently between victim and destination on the wireless link itself.
- ✗
ICMP flood
Why it's wrong here
An ICMP flood is a denial-of-service technique that saturates a target with echo requests, exhausting bandwidth; it intercepts nothing and relays no traffic. It is tempting because ICMP is used for reconnaissance and tunnelling, so it appears in attack discussions, but it would be the answer for a volumetric DoS question rather than MITM.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Key term
ICMP
ICMP is a network-layer protocol used by network devices to send error messages and operational information about network connectivity.
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.