nerdexam
CompTIA

SY0-701 · Question #599

A security administrator documented the following records during an assessment of network services: Two weeks later, the administrator performed a log review and noticed the records were changed as…

The correct answer is B. DNS poisoning. DNS poisoning (also called DNS cache poisoning or DNS spoofing) is the correct answer because the scenario describes DNS records being silently altered to point to an unauthorized external IP address - the hallmark of this attack, where an attacker corrupts a DNS resolver's…

Submitted by andres_qro· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

A security administrator documented the following records during an assessment of network services:

Two weeks later, the administrator performed a log review and noticed the records were changed as follows:

When consulting the service owner, the administrator validated that the new address was not part of the company network. Which of the following was the company most likely experiencing?

Options

  • ADDoS attack
  • BDNS poisoning
  • CRansomware compromise
  • DSpyware infection

How the community answered

(53 responses)
  • A
    15% (8)
  • B
    75% (40)
  • C
    8% (4)
  • D
    2% (1)

Explanation

DNS poisoning (also called DNS cache poisoning or DNS spoofing) is the correct answer because the scenario describes DNS records being silently altered to point to an unauthorized external IP address - the hallmark of this attack, where an attacker corrupts a DNS resolver's cache to redirect legitimate traffic to a malicious destination.

Why the distractors are wrong:

  • A (DDoS): A Distributed Denial of Service attack overwhelms a service with traffic to make it unavailable - it doesn't alter DNS records.
  • C (Ransomware): Ransomware encrypts files and demands payment; it doesn't manipulate DNS infrastructure.
  • D (Spyware): Spyware silently collects user data from a host; it doesn't modify network-level DNS records.

Memory tip: Think of DNS poisoning like a corrupt phone book - someone secretly changed the listing so that when you look up a legitimate address, you get sent to a fraudulent one instead. The key clues in any exam question are: records were changed + traffic redirected to an unknown/external address = DNS poisoning.

Topics

#DNS poisoning#Network attacks#Threats#DNS security

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice