DNS cache poisoning
An attack that plants a forged record in a DNS resolver's cache, so the resolver hands the false answer to every client that asks until the record expires.
DNS cache poisoning inserts false data into the cache of a recursive DNS resolver. A resolver keeps the answers it receives for as long as their time to live allows, so one accepted forgery is then served to every client that asks for that name, sending users to an attacker’s address. The classic method is a race: the attacker floods the resolver with forged replies, hoping one matches the transaction identifier of an outstanding query before the real answer arrives. Source port randomisation (RFC 5452) makes that guess harder.
DNS spoofing is the wider idea of forging any DNS answer, including one sent to a single client by an attacker in the path, which is a form of man-in-the-middle attack. DNS poisoning is often used for both. Cache poisoning corrupts a resolver’s data without taking control of it, which separates it from DNS hijacking. DNSSEC is the durable fix: a validating resolver rejects records from a signed zone that fail signature validation. DNS over HTTPS encrypts the path from client to resolver, but does not stop a resolver’s own cache being poisoned.
Exam relevance: a scenario is likely to describe many users sent to the same false site and ask for the attack or the control. Candidates are expected to name cache poisoning and to choose DNSSEC for origin authentication of DNS data.