SSCP Network and Communications Security Practice Question
A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)
⚠ Common exam trap
SSCP often tests the confusion between DNSSEC (integrity/authenticity) and encryption (DoH/DoT), and candidates may pick 'block port 53' as a quick fix, not realizing it breaks DNS entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement DNSSEC to validate DNS responses
Option A (Implement DNSSEC to validate DNS responses) is correct because DNSSEC adds cryptographic signatures (RRSIG) to DNS records so a resolver can verify authenticity and integrity, preventing forged or spoofed records from being accepted during a poisoning attack. Option D (Use secure DNS resolvers that enforce DNSSEC validation) is correct because even with DNSSEC deployed, the resolver must actually perform validation of the chain of trust (via DS/DNSKEY records) to reject bogus answers; resolvers that enforce validation stop poisoned data from reaching clients. Option B is wrong because blocking UDP port 53 would break legitimate DNS resolution entirely rather than prevent poisoning. Option C is wrong because disabling recursion on authoritative servers is a general hardening practice but does not by itself prevent cache poisoning of recursive resolvers. Option E is wrong because DHCP snooping protects against rogue DHCP servers and Layer 2 attacks, not DNS cache poisoning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement DNSSEC to validate DNS responses
Why this is correct
DNSSEC cryptographically signs DNS records, letting resolvers verify responses originated from the authoritative zone and were not altered in transit. This directly defeats cache poisoning, where forged replies redirect users to attacker-controlled addresses, satisfying the stem's requirement to prevent spoofed DNS data from being trusted.
- ✗
Configure firewall rules to block UDP port 53
Why it's wrong here
Blocking UDP port 53 halts all legitimate DNS resolution, including the queries clients need, without preventing cache poisoning from upstream resolvers. Firewall filtering suits restricting specific untrusted hosts, but DNS poisoning requires validating responses via DNSSEC rather than severing the protocol entirely.
- ✗
Disable DNS recursion on authoritative servers
Why it's wrong here
Disabling recursion on authoritative servers is already standard hardening; those servers never resolve external queries anyway, so it does nothing against poisoning of a recursive resolver's cache. This setting suits authoritative-only deployments, but the attack targets recursive resolvers, which must retain recursion to serve clients.
- ✓
Use secure DNS resolvers that enforce DNSSEC validation
Why this is correct
DNSSEC validation lets a resolver verify the cryptographic signature on DNS responses, so forged records injected by a poisoning attacker fail validation and are discarded. This directly satisfies the stem's requirement for a preventive countermeasure, since the resolver refuses unauthenticated data rather than caching it.
- ✗
Enable DHCP snooping on switches
Why it's wrong here
DHCP snooping filters rogue DHCP servers on layer-2 segments, protecting against address assignment spoofing, not forged DNS responses. It would be correct where unauthorised DHCP servers hand out false gateways, but DNS poisoning arrives via resolver cache corruption, which snooping never inspects.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.