Courseiva

SSCP Network and Communications Security Practice Question

A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)

⚠ Common exam trap

SSCP often tests the confusion between DNSSEC (integrity/authenticity) and encryption (DoH/DoT), and candidates may pick 'block port 53' as a quick fix, not realizing it breaks DNS entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement DNSSEC to validate DNS responses

Option A (Implement DNSSEC to validate DNS responses) is correct because DNSSEC adds cryptographic signatures (RRSIG) to DNS records so a resolver can verify authenticity and integrity, preventing forged or spoofed records from being accepted during a poisoning attack. Option D (Use secure DNS resolvers that enforce DNSSEC validation) is correct because even with DNSSEC deployed, the resolver must actually perform validation of the chain of trust (via DS/DNSKEY records) to reject bogus answers; resolvers that enforce validation stop poisoned data from reaching clients. Option B is wrong because blocking UDP port 53 would break legitimate DNS resolution entirely rather than prevent poisoning. Option C is wrong because disabling recursion on authoritative servers is a general hardening practice but does not by itself prevent cache poisoning of recursive resolvers. Option E is wrong because DHCP snooping protects against rogue DHCP servers and Layer 2 attacks, not DNS cache poisoning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement DNSSEC to validate DNS responses

    Why this is correct

    DNSSEC cryptographically signs DNS records, letting resolvers verify responses originated from the authoritative zone and were not altered in transit. This directly defeats cache poisoning, where forged replies redirect users to attacker-controlled addresses, satisfying the stem's requirement to prevent spoofed DNS data from being trusted.

  • ✗

    Configure firewall rules to block UDP port 53

    Why it's wrong here

    Blocking UDP port 53 halts all legitimate DNS resolution, including the queries clients need, without preventing cache poisoning from upstream resolvers. Firewall filtering suits restricting specific untrusted hosts, but DNS poisoning requires validating responses via DNSSEC rather than severing the protocol entirely.

  • ✗

    Disable DNS recursion on authoritative servers

    Why it's wrong here

    Disabling recursion on authoritative servers is already standard hardening; those servers never resolve external queries anyway, so it does nothing against poisoning of a recursive resolver's cache. This setting suits authoritative-only deployments, but the attack targets recursive resolvers, which must retain recursion to serve clients.

  • ✓

    Use secure DNS resolvers that enforce DNSSEC validation

    Why this is correct

    DNSSEC validation lets a resolver verify the cryptographic signature on DNS responses, so forged records injected by a poisoning attacker fail validation and are discarded. This directly satisfies the stem's requirement for a preventive countermeasure, since the resolver refuses unauthenticated data rather than caching it.

  • ✗

    Enable DHCP snooping on switches

    Why it's wrong here

    DHCP snooping filters rogue DHCP servers on layer-2 segments, protecting against address assignment spoofing, not forged DNS responses. It would be correct where unauthorised DHCP servers hand out false gateways, but DNS poisoning arrives via resolver cache corruption, which snooping never inspects.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.