Courseiva

SSCP Network and Communications Security Practice Question

A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?

⚠ Common exam trap

SSCP often tests the difference between attacks that corrupt DNS data (poisoning/spoofing) and attacks that abuse DNS as a transport or amplifier (tunneling, amplification) — candidates confuse 'DNS attack' with 'DNS poisoning' without checking whether records were actually altered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS poisoning

DNS poisoning (also called DNS cache poisoning or spoofing) occurs when an attacker injects forged DNS records into a resolver's cache, causing it to return incorrect IP addresses for legitimate domain names. The symptom described — a compromised resolver cache returning wrong IPs — is the textbook definition of this attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS amplification attack

    Why it's wrong here

    DNS amplification floods a victim with large responses using spoofed queries; it does not alter cached records. It is tempting because both involve DNS abuse, but cache poisoning is the correct term when a resolver returns falsified addresses for legitimate domains, redirecting users to attacker-controlled hosts.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood exhausts TCP connection state on a server; it does not modify DNS cache entries. It is tempting because both are denial-of-service techniques, but the stem describes falsified name resolution, which is cache poisoning, not transport-layer resource exhaustion.

  • ✗

    DNS tunneling

    Why it's wrong here

    Tunneling uses DNS to exfiltrate data, not corrupt records.

  • ✓

    DNS poisoning

    Why this is correct

    DNS poisoning corrupts a resolver's cache with forged records, causing legitimate domain names to resolve to attacker-supplied IP addresses, satisfying the stem's symptom of incorrect addresses for valid domains. Spoofing intercepts a single response; poisoning persists in the cache for the record's TTL.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.