Payroll staff report the familiar portal URL opening a lookalike login page. Recursive resolver cache shows unexpected A records for the official hostname. Which malicious activity indicator fits best?
Select an answer to reveal the explanation.
Short Explanation
If the name is right but the IP is wrong and the page looks almost real, DNS got poisoned. Users land on a fake payroll door because the cache lied—not because allow lists or firewalls went soft.
Full Explanation
DNS cache poisoning injects fraudulent resolution data so clients reach attacker-controlled lookalike sites while believing they used the legitimate hostname. Allow listing, host firewalls, and decommissioning are mitigation or hygiene controls, not explanations for unexpected cached A records leading to fake login pages.