An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?
The attacker terminates two separate TCP sessions — one with the client, one with the server — and relays traffic between them, so each endpoint authenticates against the attacker rather than the genuine peer. This active relay, not passive eavesdropping, defines the man-in-the-middle scenario described.
Why this answer
A man-in-the-middle (MITM) attack occurs when an adversary positions themselves between two communicating parties, establishing separate connections with each and relaying (or altering) traffic while both sides believe they are communicating directly. The scenario describes exactly this relay behavior. The attacker can eavesdrop, modify, or inject data because neither endpoint detects the intermediary.
Exam trap
The trap here is conflating MITM with sniffing or replay — candidates must recognize that MITM specifically requires the attacker to sit inline and relay traffic between two parties, not merely observe or retransmit it.
How to eliminate wrong answers
Option A is wrong because phishing is a social-engineering attack that tricks users into revealing credentials or clicking malicious links; it does not involve transparently relaying traffic between two hosts. Option C is wrong because a replay attack captures and retransmits previously valid data (such as an authentication token) to impersonate a legitimate party, rather than maintaining a live relay between client and server. Option D is wrong because a DoS attack aims to exhaust resources and deny availability, not to intercept and relay communications covertly.