exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 42 discussion

Actual exam question from CompTIA's SY0-601
Question #: 42
Topic #: 1
[All SY0-601 Questions]

A security analyst is investigating some users who are being redirected to a fake website that resembles www.comptia.org. The following output was found on the naming server of the organization:

Which of the following attacks has taken place?

  • A. Domain reputation
  • B. Domain hijacking
  • C. Disassociation
  • D. DNS poisoning
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
stoneface
Highly Voted 2 years, 8 months ago
Selected Answer: D
DNS server cache poisoning aims to corrupt the records held by the DNS server itself. This can be accomplished by performing DoS against the server that holds the authorized records for the domain, and then spoofing replies to requests from other name servers. Another attack involves getting the victim name server to respond to a recursive query from the attacking host. A recursive query compels the DNS server to query the authoritative server for the answer on behalf of the client.
upvoted 34 times
...
RileyG
Highly Voted 2 years ago
Domain Hijacking is the act of changing the registration of a domain name without the permission of the original owner, or by abuse of privileges on domain hosting and domain registrar systems. DNS poisoning is when false information is entered into a DNS Cache, so that DNS queries return an incorrect response that directs users to the wrong website. The answer is D because the question says "redirected to a fake website" - and we are also looking at a DNS table in the picture which means the answer is D.
upvoted 8 times
...
RyanL26
Most Recent 1 year, 1 month ago
Selected Answer: D
DNS Poisoning vs Domain Hijacking: DNS = IP Address. It changes the IP Addresses. Domain = DNS Records. It changes the name of the Domain. DNS Reg is getting pointed to another server. Answer: D
upvoted 2 times
...
alicia2024
1 year, 3 months ago
Selected Answer: D
DNS poisoning involves manipulating the Domain Name System (DNS) cache of a DNS server to redirect domain name resolutions to malicious IP addresses. In this scenario, users are being redirected to a fake website resembling www.comptia.org, indicating that the DNS records for the legitimate domain have been tampered with.
upvoted 2 times
...
Rr_Jay
1 year, 4 months ago
It is not hijacking as the system administer can still see the dns record which mean he still has access to it , if this got hijacked the wouldn't have access to it isn't it ? And DNS poisonings redirect the user to the fake website . that why i think the correct answer is DNS poisonings .
upvoted 1 times
...
Tolis21
1 year, 5 months ago
I don't get something who decides the correct answer?
upvoted 3 times
geocis
1 year, 4 months ago
It's up to you to do the research and figure out which one is the correct answer. If this site had all the right answers, it would probably be shut down. The way I see it, at least you're presented with all the possible questions on the test.
upvoted 2 times
...
...
Teleco0997
1 year, 6 months ago
Selected Answer: D
"SOME users are being redirected to a fake website" = DNS poisoning it cant be domain hijacking as it would be all users
upvoted 4 times
Teleco0997
1 year, 6 months ago
also, using the info of the DNS table: in this case, the DNS server has incorrect mappings, associating the legitimate www.comptia.org with the malicious IP address 192.168.1.10. When users attempt to access www.comptia.org, they are redirected to that fake website
upvoted 1 times
...
...
n00r1
1 year, 6 months ago
DNS poisoning is the corruption of the dns, domain hijacking requires the domain be transferred to unauthorized party.
upvoted 1 times
...
BlackSpider
1 year, 8 months ago
Selected Answer: D
it is only happening to some users. This is the key here.
upvoted 2 times
vitasaia
1 year, 6 months ago
They're not saying "only". It could be that the others have not tried or reported it. It's not clear.
upvoted 1 times
...
...
DannaD
1 year, 9 months ago
I believe this is hijacking because the attacker has already hijacked the DNS management before attempting to poison the DNS
upvoted 3 times
...
RevolutionaryAct
1 year, 9 months ago
Selected Answer: B
It's hijacking as that is another DNS not your own (which would be DNS poisoning) https://www.malwarebytes.com/cybersecurity/business/what-is-dns-hijacking
upvoted 1 times
daddylonglegs
1 year, 7 months ago
4th time
upvoted 2 times
Mpololo
1 year, 6 months ago
Literally....
upvoted 2 times
...
...
...
sujon_london
1 year, 9 months ago
Answer is B. After a domain hijacking incident, the attackers may have full control over the domain name settings, including the ability to change the domain name and IP address associated with it. Change Domain Name: The attackers can modify the domain's DNS settings and point it to a different domain name. In this scenario exactly happen domain hijacked maybe through phishing or by other means, then changed the dns name or IP addresses. Considering first domain hijacked and then changes IP address. Where most comments suggesting DNS poisoning. Indeed answer should be B followed by question given sequence clues. As many things can happen once domain hijacked.
upvoted 4 times
...
Protract8593
1 year, 10 months ago
Selected Answer: D
The given scenario describes a DNS poisoning attack. In this attack, the attacker has manipulated the DNS records on the naming server to associate the domain name "www.comptia.org" with a malicious IP address (192.168.1.10). As a result, when users try to access the legitimate website www.comptia.org, they are redirected to a fake website hosted at the malicious IP address.
upvoted 4 times
Kraken84
1 year, 9 months ago
SOUNDS GOOD, but what in this question instigates that 192.168.1.10 is a malicious IP address? I wanna believe your answer, but no where does it state that this is a malicious IP address.
upvoted 2 times
Kingbumi777
1 year, 8 months ago
The IP 192.168.1.10 doesn't follow the standard of the other IP's and it is also a private IP address. Regardless, if you ever see the IP "192.168.1.X", assume it doesn't belong.
upvoted 1 times
...
HCM1985
1 year, 8 months ago
Following throught the question, the domain is comptia.org, and we can assume www has a fake IP because it's for a different network from all the other records (I know it's silly and that in itself does not mean anything, but we work with what we have).
upvoted 1 times
...
...
...
Haykinz
1 year, 10 months ago
Selected Answer: B
Option B: Several things can happen when a domain is hijacked. The hackers may take control of the website and use it for malicious purposes, such as spreading malware or conducting phishing attacks. They could also redirect traffic to other websites, resulting in lost sales or damage to your brand reputation The D is correct because if DNS poisoning occurs most times the website is same and not a resemblance. During a DNS poisoning attack, a hacker substitutes the address for a valid website for an imposter. Once completed, that hacker can steal valuable information, like passwords and account numbers. Or the hacker can simply refuse to load the spoofed site. Someone browsing the web may never know that DNS spoofing is happening. The person may visit a site that looks perfectly normal, and even functions somewhat normally, so everything seems safe.
upvoted 2 times
...
Dutch012
2 years ago
Okay, now it's evident that DNS poisoning is the answer to Question 1, yay!
upvoted 1 times
...
TheGuitarMan_61
2 years, 1 month ago
Stoneface; agree 100% "some users" takes away the Domain Hijacking answer to Poisoning, as it it is only Some Users.
upvoted 3 times
Abdul2107
2 years, 1 month ago
Smart notice
upvoted 2 times
...
...
Neither_you_nor_me
2 years, 1 month ago
Selected Answer: D
This seems to be the practical version of the first question
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...