Why Are Only Internal Kiosk Credentials Compromised?
A security analyst discovers that a large number of employee credentials had been stolen and were being sold on the dark web. The analyst investigates and discovers that some hourly employee credentials were compromised, but salaried employee credentials were not affected. Most employees clocked in and out while they were inside the building using one of the kiosks connected to the network. However, some clocked out and recorded their time after leaving to go home. Only those who clocked in and out while inside the building had credentials stolen. Each of the kiosks are on different floors, and there are multiple routers, since the business segments environments for certain business functions. Hourly employees are required to use a website called acmetimekeeping.com to clock in and out. This website is accessible from the internet. Which of the following is the most likely reason for this compromise?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests network-layer vs application-layer attacks, with the common trap being ARP poisoning due to its reputation for local credential interception.
This Security+ question tests your ability to identify DNS poisoning as the root cause of selective credential theft. The analysis confirms option C is correct because internal DNS redirection isolates the compromise to on-site networks.
Option D (ARP poisoning) is frequently chosen because it also intercepts traffic, but it fails here since ARP is a Layer 2 protocol confined to single broadcast domains and cannot span the multiple routed segments described.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
DNS poisoning on internal resolvers redirects corporate traffic for acmetimekeeping.com to an attacker-controlled server before reaching the legitimate host. Employees using internal kiosks are silently forwarded to the malicious domain where their credentials are captured and relayed to the actual site, preserving their session. This explains why remote users clocking out from home remain unaffected, as they bypass the poisoned internal DNS infrastructure entirely.Why the Other Options Are Wrong
ARP poisoning operates at Layer 2 and cannot traverse the multiple routers and segmented business environments mentioned in the prompt. A compromised web application would impact every visitor regardless of location, contradicting the observation that only on-site staff were targeted. Brute-force attacks rely on repeated login attempts rather than network-level redirection, making them inconsistent with the observed access patterns.Community Comment Notes
Learners consistently highlight that broadcast-domain limitations rule out local switching attacks. As one commenter noted, 'The question says that multiple routers are in use within the building,' which definitively eliminates Layer 2 threats. Another user emphasized that if the site itself were infected, remote clock-outs would have failed just like the office ones. The consensus correctly identifies internal resolver manipulation as the only vector matching the geographic restriction.Exam Strategy
Always map the attack scope to the network topology provided in the scenario. When segmentation or multiple routers are mentioned, immediately eliminate Layer 2 attacks like ARP or MAC flooding since they cannot cross routed boundaries.
Frequently Asked Questions
Why does ARP poisoning fail here?
ARP operates at Layer 2 and is confined to a single broadcast domain. The presence of multiple routers prevents ARP spoofing from affecting kiosks on different floors.
Could the website itself be compromised?
No. If the web application contained malicious code, every visitor—including remote employees—would have their credentials stolen, contradicting the scenario.