SSCP Network and Communications Security Practice Question
A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?
⚠ Common exam trap
SSCP often tests the difference between attacks that corrupt DNS data (poisoning/spoofing) and attacks that abuse DNS as a transport or amplifier (tunneling, amplification) — candidates confuse 'DNS attack' with 'DNS poisoning' without checking whether records were actually altered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS poisoning
DNS poisoning (also called DNS cache poisoning or spoofing) occurs when an attacker injects forged DNS records into a resolver's cache, causing it to return incorrect IP addresses for legitimate domain names. The symptom described — a compromised resolver cache returning wrong IPs — is the textbook definition of this attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS amplification attack
Why it's wrong here
DNS amplification floods a victim with large responses using spoofed queries; it does not alter cached records. It is tempting because both involve DNS abuse, but cache poisoning is the correct term when a resolver returns falsified addresses for legitimate domains, redirecting users to attacker-controlled hosts.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts TCP connection state on a server; it does not modify DNS cache entries. It is tempting because both are denial-of-service techniques, but the stem describes falsified name resolution, which is cache poisoning, not transport-layer resource exhaustion.
- ✗
DNS tunneling
Why it's wrong here
Tunneling uses DNS to exfiltrate data, not corrupt records.
- ✓
DNS poisoning
Why this is correct
DNS poisoning corrupts a resolver's cache with forged records, causing legitimate domain names to resolve to attacker-supplied IP addresses, satisfying the stem's symptom of incorrect addresses for valid domains. Spoofing intercepts a single response; poisoning persists in the cache for the record's TTL.
Visual reference
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.