Chapter 43: Network Attacks and Defenses
This chapter follows the topics shown in the Networking chapter menu. Work through each section in order, then use the review questions to check recall and troubleshooting reasoning.
43.1 Reconnaissance
Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.2 Passive Reconnaissance
Passive Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Passive Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.3 Active Reconnaissance
Active Reconnaissance is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Active Reconnaissance in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.4 Port Scanning
Port Scanning is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Port Scanning in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.5 Ping Sweeps
Ping is a basic reachability and round-trip-time test. A failed ping does not always prove the destination is down because policy may block ICMP.
Example: ping the local loopback, local interface, default gateway, remote IP, and finally a hostname. The first failed step helps narrow the fault domain, but remember that ICMP filtering can produce false negatives.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Command or data example
ping 192.0.2.1
43.6 ARP Spoofing
ARP maps an IPv4 address to a local-layer MAC address on an IPv4 LAN. A host normally uses ARP only for destinations it considers local, or for the default gateway when the destination is remote.
Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Command or data example
arp -a
43.7 Dynamic ARP Inspection
ARP maps an IPv4 address to a local-layer MAC address on an IPv4 LAN. A host normally uses ARP only for destinations it considers local, or for the default gateway when the destination is remote.
Example: place Dynamic ARP Inspection in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Command or data example
arp -a
43.8 DNS Poisoning
DNS translates names into resource records such as IP addresses, aliases, mail-routing information, and service data. Client caching and TTL values affect how quickly changes become visible.
Example: a user can reach 203.0.113.20 but cannot reach server.example by name. That difference points toward name resolution, DNS reachability, record content, cache state, or search-suffix behavior rather than basic IP routing.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.9 Rogue DHCP
DHCP automatically supplies IP configuration such as an address, mask or prefix, gateway, DNS servers, and lease information. IPv4 clients commonly use the Discover, Offer, Request, Acknowledge exchange.
Example: a laptop joins a LAN with no manual IP configuration. It broadcasts or multicasts the appropriate discovery traffic, receives an offer, requests the selected lease, and then applies the address, gateway, DNS settings, and lease timers.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.10 DHCP Starvation
DHCP automatically supplies IP configuration such as an address, mask or prefix, gateway, DNS servers, and lease information. IPv4 clients commonly use the Discover, Offer, Request, Acknowledge exchange.
Example: a laptop joins a LAN with no manual IP configuration. It broadcasts or multicasts the appropriate discovery traffic, receives an offer, requests the selected lease, and then applies the address, gateway, DNS settings, and lease timers.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.11 MAC Flooding
MAC Flooding is a Layer 2 concept involving Ethernet hardware addressing or switch forwarding state. Switches learn source MAC addresses and use destination MAC information to choose whether to forward, flood, or filter frames.
Example: place MAC Flooding in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.12 VLAN Hopping
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Command or data example
ping 192.0.2.1
43.13 On-Path Attacks
PAT lets many inside hosts share one or a small number of public IPv4 addresses by tracking transport protocol and port mappings.
Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
43.14 DoS
DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place DoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.15 DDoS
DDoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place DDoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.16 Volumetric Attacks
Volumetric Attacks is a network-security concept. A sound design identifies the protected asset, trust boundary, possible abuse path, preventive controls, detection signals, and recovery steps.
Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
43.17 Protocol Attacks
Protocol Attacks is a network-security concept. A sound design identifies the protected asset, trust boundary, possible abuse path, preventive controls, detection signals, and recovery steps.
Example: a monitoring system reports unusual address mappings and traffic redirection. Preserve evidence, compare neighbor or MAC tables with known values, isolate affected segments, and verify the control that should prevent the spoofing technique.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
43.18 Application-Layer DoS
Application-Layer DoS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Application-Layer DoS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.19 SYN Flood
SYN Flood is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place SYN Flood in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.20 Reflection
Reflection is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Reflection in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.21 Amplification
Amplification is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Amplification in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.22 Rogue AP
Rogue AP is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Rogue AP in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.23 Evil Twin
Evil Twin is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Evil Twin in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.24 Deauthentication
Deauthentication is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Deauthentication in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.25 Brute Force
Brute Force is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Brute Force in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.26 Password Spraying
Password Spraying is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Password Spraying in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.27 Credential Stuffing
Credential Stuffing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Credential Stuffing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.28 Phishing
Phishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Phishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.29 Spear Phishing
Spear Phishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Spear Phishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.30 Smishing
Smishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Smishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.31 Vishing
Vishing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Vishing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.32 Tailgating
Tailgating is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Tailgating in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.33 Shoulder Surfing
Shoulder Surfing is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Shoulder Surfing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.34 Malware Indicators
Malware Indicators is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Malware Indicators in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.35 Botnets
Botnets is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Botnets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.36 Ransomware
Ransomware is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Ransomware in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.37 Zero-Day Vulnerabilities
Zero-Day Vulnerabilities is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Zero-Day Vulnerabilities in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.38 IDS/IPS
IDS/IPS is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place IDS/IPS in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.39 Honeypots/Honeynets
Honeypots/Honeynets is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Honeypots/Honeynets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
43.40 Defense in Depth
Defense in Depth is one of the core topics in Network Attacks and Defenses. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Defense in Depth in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.