nerdexam
Cisco

200-201 · Question #327

Endpoint logs indicate that a machine has obtained an unusual gateway address and unusual DNS servers via DHCP. Which type of attack is occurring?

The correct answer is C. man in the middle attack. In a man-in-the-middle attack, an attacker intercepts communication between two parties, often without their knowledge, and can alter the traffic passing between them. By providing the compromised or "unusual" gateway address and DNS servers via DHCP, the attacker can reroute…

Submitted by mateo_ar· Mar 6, 2026Network Intrusion Analysis

Question

Endpoint logs indicate that a machine has obtained an unusual gateway address and unusual DNS servers via DHCP. Which type of attack is occurring?

Options

  • Aevasion methods
  • Bphishing
  • Cman in the middle attack
  • Dcommand injection

How the community answered

(15 responses)
  • A
    7% (1)
  • C
    93% (14)

Explanation

In a man-in-the-middle attack, an attacker intercepts communication between two parties, often without their knowledge, and can alter the traffic passing between them. By providing the compromised or "unusual" gateway address and DNS servers via DHCP, the attacker can reroute the network traffic from the affected machine through their controlled gateway or DNS servers. This allows the attacker to intercept, monitor, or manipulate the communication between the victim machine and the intended network resources, potentially facilitating various forms of data interception, modification, or unauthorized access.

Topics

#Man-in-the-Middle (MITM)#DHCP spoofing#Network attacks#DNS redirection

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice