A security administrator documented the following records during an assessment of network services: Two weeks later, the administrator performed a log review and noticed the records were changed as follows: When consulting the service owner, the administrator validated that the new address was not part of the company network. Which of the following was the company most likely experiencing?
Choose an answer
Tap an option to check your answer.
Correct answer: DNS poisoning.
Why this is the answer
The company was most likely experiencing DNS poisoning. The initial log showed a legitimate internal IP address (192.168.1.100) associated with a service. Two weeks later, the same service was resolved to an external, unauthorized IP address (10.1.1.1), indicating that the DNS records were manipulated to redirect traffic to a malicious server. A DDoS attack would involve overwhelming the service with traffic, not altering DNS records. Ransomware encrypts data and demands payment, which isn't indicated by changed DNS entries. Spyware collects information discreetly, but doesn't directly involve redirecting network services via DNS manipulation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed