Why Are Only Internal Kiosk Credentials Compromised?

DNS Security & Internal Network Threats
Answer Correct answer: C — Internal DNS servers were poisoned to redirect acmetimekeeping.com to a malicious domain that intercepted and relayed the credentials to the real site.

A security analyst discovers that a large number of employee credentials had been stolen and were being sold on the dark web. The analyst investigates and discovers that some hourly employee credentials were compromised, but salaried employee credentials were not affected. Most employees clocked in and out while they were inside the building using one of the kiosks connected to the network. However, some clocked out and recorded their time after leaving to go home. Only those who clocked in and out while inside the building had credentials stolen. Each of the kiosks are on different floors, and there are multiple routers, since the business segments environments for certain business functions. Hourly employees are required to use a website called acmetimekeeping.com to clock in and out. This website is accessible from the internet. Which of the following is the most likely reason for this compromise?

  1. A brute-force attack was used against the time-keeping website to scan for common passwords.
  2. A malicious actor compromised the time-keeping website with malicious code using an unpatched vulnerability on the site, stealing the credentials.
  3. The internal DNS servers were poisoned and were redirecting acmetimekeeping.com to a malicious domain that intercepted the credentials and then passed them through to the real site. Correct Answer
  4. ARP poisoning affected the machines in the building and caused the kiosks to send a copy of all the submitted credentials to a malicious machine.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests network-layer vs application-layer attacks, with the common trap being ARP poisoning due to its reputation for local credential interception.

This Security+ question tests your ability to identify DNS poisoning as the root cause of selective credential theft. The analysis confirms option C is correct because internal DNS redirection isolates the compromise to on-site networks.

Option D (ARP poisoning) is frequently chosen because it also intercepts traffic, but it fails here since ARP is a Layer 2 protocol confined to single broadcast domains and cannot span the multiple routed segments described.

Community Discussion (12 comments)

sysics 👍 10 Selected: C
C makes more sense to me. BTW the question is tooo long to read.
LinkinTheStinkin 👍 5 Selected: C
The question says that multiple routers are in use within the building. This rules out ARP poisoning, since ARP is a layer 2 protocol, and limited to a single broadcast domain, it would only affect a portion of the network. It says people at home were able to use the website and not have their credentials compromised, so the website itself has no issue. The only answer it can be is is C.
Rami1996 👍 2 Selected: B
there are some potential issues with option C: Complexity: DNS poisoning attacks, while possible, typically require a significant level of access to internal systems. If internal DNS servers were compromised, it would likely have broader implications beyond just redirecting traffic to a single website. Detection: DNS poisoning attacks are usually detectable, especially if employees were being redirected to a malicious domain. Such activities often trigger security alerts or anomalies that would prompt investigation. While option C offers a plausible explanation, it may not be the most likely scenario given the complexity and detectability of DNS poisoning attacks.
BD69 👍 1 Selected: C
With so many internal DNS servers (especially windows domains) default settings to allow non-authoritative changes to DNS records, answer C is the most likely via MITM attack. Answer B is certainly possible, however, that would affect every company that uses that service (this was not mentioned), not just the company in question. Answer D would work too, but this requires a bit more work, non-locked down switches and would be identified quickly by security & network software (immediate conflict alerts) .
MF757 👍 1 Selected: B
The fact that only hourly employees who clocked in and out while inside the building had their credentials stolen suggests that the compromise is likely related to the usage of the time-keeping website.
TM78 👍 1 Selected: D
D. DNS Poisoning You can get a very basic explanation here (time stamp 5:50 if you don’t care to watch the whole video): https://youtu.be/7MT1F0O3_Yw?si=K7Rung_UtsGcnX7Y If you don’t feel the warm fuzzies about clicking some random link, go YouTube > search DNS Cache Poisoning - Computerphile. The reason why I don’t think it is ARP is because of an assumption (yeah, bad word) that the time card website is https, meaning that the information intercepted by the bad actor should be encrypted and unable to use.
7308365 👍 3
ARP poisoning attacks can compromise systems and redirect network traffic to the threat actor, who leverages their position to insert malware and steal sensitive data. Only those who clocked in and out while inside the building had credentials stolen. D. ARP poisoning affected the machines in the building and caused the kiosks to send a copy of all the submitted credentials to a malicious machine.
Payu1994 👍 2
D. ARP poisoning affected the machines in the building and caused the kiosks to send a copy of all the submitted credentials to a malicious machine. Explanation: ARP Poisoning (Option D): ARP (Address Resolution Protocol) poisoning involves manipulating the ARP cache on a local network, leading to the association of incorrect MAC addresses with IP addresses. In this scenario, if ARP poisoning occurred, it could lead to the kiosks sending a copy of the submitted credentials to a malicious machine before reaching the legitimate server. This could happen if the ARP cache on the local network was manipulated to redirect traffic through a malicious machine.
licks0re 👍 2 Selected: C
Clearly C, see comments below.
johnabayot 👍 2 Selected: B
This option explains why only the hourly employees who used the kiosks inside the building were affected, and not the salaried employees or the hourly employees who clocked out from home. If the time-keeping website was compromised, then anyone who accessed it from the kiosks would have their credentials stolen by the malicious code. The other options do not account for this scenario.
Hs1208 👍 5 Selected: C
C. The internal DNS servers were poisoned and were redirecting acmetimekeeping.com to a malicious domain that intercepted the credentials and then passed them through to the real site.
Baba111222 👍 4 Selected: C
It can't be B. If the actual website was compromised, employees signing after they left would also be affected. In this case only ones using the kiosks connected to the same network were affected, thus DNS poisoning being the only logical option here.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

DNS poisoning on internal resolvers redirects corporate traffic for acmetimekeeping.com to an attacker-controlled server before reaching the legitimate host. Employees using internal kiosks are silently forwarded to the malicious domain where their credentials are captured and relayed to the actual site, preserving their session. This explains why remote users clocking out from home remain unaffected, as they bypass the poisoned internal DNS infrastructure entirely.

Why the Other Options Are Wrong

ARP poisoning operates at Layer 2 and cannot traverse the multiple routers and segmented business environments mentioned in the prompt. A compromised web application would impact every visitor regardless of location, contradicting the observation that only on-site staff were targeted. Brute-force attacks rely on repeated login attempts rather than network-level redirection, making them inconsistent with the observed access patterns.

Community Comment Notes

Learners consistently highlight that broadcast-domain limitations rule out local switching attacks. As one commenter noted, 'The question says that multiple routers are in use within the building,' which definitively eliminates Layer 2 threats. Another user emphasized that if the site itself were infected, remote clock-outs would have failed just like the office ones. The consensus correctly identifies internal resolver manipulation as the only vector matching the geographic restriction.

Exam Strategy

Always map the attack scope to the network topology provided in the scenario. When segmentation or multiple routers are mentioned, immediately eliminate Layer 2 attacks like ARP or MAC flooding since they cannot cross routed boundaries.

Frequently Asked Questions

Why does ARP poisoning fail here?

ARP operates at Layer 2 and is confined to a single broadcast domain. The presence of multiple routers prevents ARP spoofing from affecting kiosks on different floors.

Could the website itself be compromised?

No. If the web application contained malicious code, every visitor—including remote employees—would have their credentials stolen, contradicting the scenario.

Related Analysis

← Back to SY0-601 Study Guide