nerdexam
CompTIA

N10-009 · Question #160

A network administrator suspects users are being sent to malware sites that are posing as legitimate sites. The network administrator investigates and discovers that user workstations are configured…

The correct answer is C. DHCP snooping. DHCP snooping is a security feature on network switches that helps to prevent unauthorized (rogue) DHCP servers from assigning IP addresses to clients. By implementing DHCP snooping, the network administrator can restrict DHCP responses to authorized servers only, preventing…

Submitted by weili_xi· Mar 6, 2026Network Security

Question

A network administrator suspects users are being sent to malware sites that are posing as legitimate sites. The network administrator investigates and discovers that user workstations are configured with incorrect DNS IP addresses. Which of the following should the network administrator implement to prevent this from happening again?

Options

  • ADynamic ARP inspection
  • BAccess control lists
  • CDHCP snooping
  • DPort security

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    83% (29)
  • D
    9% (3)

Explanation

DHCP snooping is a security feature on network switches that helps to prevent unauthorized (rogue) DHCP servers from assigning IP addresses to clients. By implementing DHCP snooping, the network administrator can restrict DHCP responses to authorized servers only, preventing unauthorized DHCP configurations, such as incorrect DNS IPs, from being assigned to clients. This helps prevent man-in-the-middle attacks where malicious actors misconfigure DNS to redirect users to fraudulent sites.

Community Discussion

No community discussion yet for this question.

Full N10-009 Practice