🎓 EASYTUTORGUIDE

Practical tutorials, tools, courses, digital skills, and business promotion.

★ Free Learning

Chapter 43 — Network Attacks and Defenses

A complete networking lesson based on the course chapter menu.

40 topicsPractical examplesTroubleshooting checksReview Q&A
Estimated reading time0% read

Chapter 43: Network Attacks and Defenses

This chapter follows the topics shown in the Networking chapter menu. Work through each section in order, then use the review questions to check recall and troubleshooting reasoning.

43.1 Reconnaissance

Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Reconnaissance without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.2 Passive Reconnaissance

Passive Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Passive Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Passive Reconnaissance without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.3 Active Reconnaissance

Active Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Active Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Active Reconnaissance without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.4 Port Scanning

Port Scanning is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Port Scanning in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Port Scanning without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.5 Ping Sweeps

Ping is a basic reachability and round-trip-time test. A failed ping does not always prove the destination is down because policy may block ICMP.

Example: ping the local loopback, local interface, default gateway, remote IP, and finally a hostname. The first failed step helps narrow the fault domain, but remember that ICMP filtering can produce false negatives.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.

Command or data example

ping 192.0.2.1
Practice: Practice: explain Ping Sweeps without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.6 ARP Spoofing

ARP maps an IPv4 address to a local-layer MAC address on an IPv4 LAN. A host normally uses ARP only for destinations it considers local, or for the default gateway when the destination is remote.

Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.

Command or data example

arp -a
Practice: Practice: explain ARP Spoofing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.7 Dynamic ARP Inspection

ARP maps an IPv4 address to a local-layer MAC address on an IPv4 LAN. A host normally uses ARP only for destinations it considers local, or for the default gateway when the destination is remote.

Example: place Dynamic ARP Inspection in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.

Command or data example

arp -a
Practice: Practice: explain Dynamic ARP Inspection without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.8 DNS Poisoning

DNS translates names into resource records such as IP addresses, aliases, mail-routing information, and service data. Client caching and TTL values affect how quickly changes become visible.

Example: a user can reach 203.0.113.20 but cannot reach server.example by name. That difference points toward name resolution, DNS reachability, record content, cache state, or search-suffix behavior rather than basic IP routing.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain DNS Poisoning without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.9 Rogue DHCP

DHCP automatically supplies IP configuration such as an address, mask or prefix, gateway, DNS servers, and lease information. IPv4 clients commonly use the Discover, Offer, Request, Acknowledge exchange.

Example: a laptop joins a LAN with no manual IP configuration. It broadcasts or multicasts the appropriate discovery traffic, receives an offer, requests the selected lease, and then applies the address, gateway, DNS settings, and lease timers.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Rogue DHCP without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.10 DHCP Starvation

DHCP automatically supplies IP configuration such as an address, mask or prefix, gateway, DNS servers, and lease information. IPv4 clients commonly use the Discover, Offer, Request, Acknowledge exchange.

Example: a laptop joins a LAN with no manual IP configuration. It broadcasts or multicasts the appropriate discovery traffic, receives an offer, requests the selected lease, and then applies the address, gateway, DNS settings, and lease timers.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain DHCP Starvation without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.11 MAC Flooding

MAC Flooding is a Layer 2 concept involving Ethernet hardware addressing or switch forwarding state. Switches learn source MAC addresses and use destination MAC information to choose whether to forward, flood, or filter frames.

Example: place MAC Flooding in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain MAC Flooding without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.12 VLAN Hopping

A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.

Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.

Command or data example

ping 192.0.2.1
Practice: Practice: explain VLAN Hopping without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.13 On-Path Attacks

PAT lets many inside hosts share one or a small number of public IPv4 addresses by tracking transport protocol and port mappings.

Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.

What to check

  • Identify the trust boundary and the traffic that should be permitted or denied.
  • Check authentication, authorization, encryption, policy order, logs, and time synchronization.
  • Verify the control with an allowed test and a denied test so policy behavior is observable.
Practice: Practice: explain On-Path Attacks without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.14 DoS

DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place DoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain DoS without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.15 DDoS

DDoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place DDoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain DDoS without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.16 Volumetric Attacks

Volumetric Attacks is a network-security concept. A sound design identifies the protected asset, trust boundary, possible abuse path, preventive controls, detection signals, and recovery steps.

Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.

What to check

  • Identify the trust boundary and the traffic that should be permitted or denied.
  • Check authentication, authorization, encryption, policy order, logs, and time synchronization.
  • Verify the control with an allowed test and a denied test so policy behavior is observable.
Practice: Practice: explain Volumetric Attacks without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.17 Protocol Attacks

Protocol Attacks is a network-security concept. A sound design identifies the protected asset, trust boundary, possible abuse path, preventive controls, detection signals, and recovery steps.

Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.

What to check

  • Identify the trust boundary and the traffic that should be permitted or denied.
  • Check authentication, authorization, encryption, policy order, logs, and time synchronization.
  • Verify the control with an allowed test and a denied test so policy behavior is observable.
Practice: Practice: explain Protocol Attacks without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.18 Application-Layer DoS

Application-Layer DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Application-Layer DoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Application-Layer DoS without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.19 SYN Flood

SYN Flood is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place SYN Flood in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain SYN Flood without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.20 Reflection

Reflection is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Reflection in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Reflection without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.21 Amplification

Amplification is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Amplification in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Amplification without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.22 Rogue AP

Rogue AP is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Rogue AP in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Rogue AP without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.23 Evil Twin

Evil Twin is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Evil Twin in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Evil Twin without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.24 Deauthentication

Deauthentication is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Deauthentication in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Deauthentication without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.25 Brute Force

Brute Force is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Brute Force in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Brute Force without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.26 Password Spraying

Password Spraying is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Password Spraying in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Password Spraying without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.27 Credential Stuffing

Credential Stuffing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Credential Stuffing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Credential Stuffing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.28 Phishing

Phishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Phishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Phishing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.29 Spear Phishing

Spear Phishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Spear Phishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Spear Phishing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.30 Smishing

Smishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Smishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Smishing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.31 Vishing

Vishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Vishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Vishing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.32 Tailgating

Tailgating is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Tailgating in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Tailgating without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.33 Shoulder Surfing

Shoulder Surfing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Shoulder Surfing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Shoulder Surfing without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.34 Malware Indicators

Malware Indicators is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Malware Indicators in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Malware Indicators without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.35 Botnets

Botnets is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Botnets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Botnets without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.36 Ransomware

Ransomware is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Ransomware in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Ransomware without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.37 Zero-Day Vulnerabilities

Zero-Day Vulnerabilities is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Zero-Day Vulnerabilities in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Zero-Day Vulnerabilities without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.38 IDS/IPS

IDS/IPS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place IDS/IPS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain IDS/IPS without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.39 Honeypots/Honeynets

Honeypots/Honeynets is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Honeypots/Honeynets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Honeypots/Honeynets without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

43.40 Defense in Depth

Defense in Depth is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

Example: place Defense in Depth in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.

What to check

  • Identify which OSI/TCP-IP layer and device type are primarily responsible.
  • Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
  • Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Practice: Practice: explain Defense in Depth without reading the definition. Then draw or describe one network where it is used, name one failure symptom, and list the first two checks you would perform.

Chapter 43 Review Questions

1. What should you remember about Reconnaissance?

Answer: Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

2. What should you remember about Ping Sweeps?

Answer: Ping is a basic reachability and round-trip-time test. A failed ping does not always prove the destination is down because policy may block ICMP.

3. What should you remember about DHCP Starvation?

Answer: DHCP automatically supplies IP configuration such as an address, mask or prefix, gateway, DNS servers, and lease information. IPv4 clients commonly use the Discover, Offer, Request, Acknowledge exchange.

4. What should you remember about DoS?

Answer: DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

5. What should you remember about Application-Layer DoS?

Answer: Application-Layer DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

6. What should you remember about Evil Twin?

Answer: Evil Twin is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

7. What should you remember about Credential Stuffing?

Answer: Credential Stuffing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

8. What should you remember about Vishing?

Answer: Vishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

9. What should you remember about Ransomware?

Answer: Ransomware is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.

10. What should you remember about Defense in Depth?

Answer: Defense in Depth is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.