CND (312-38) Network Defense Simulation
Learn to differentiate between risk management formulas and the core definition of a cyber attack. This scenario tests your understanding of threat concepts and attack anatomy.
Network Scenario
You are a Network Security Analyst monitoring the external Web Application Firewall (WAF) and IDS sensors for a financial institution. You receive a series of high-priority alerts indicating a targeted intrusion attempt against the customer login portal.
To properly classify this event in your incident tracking system and update your threat models, you must break down the anatomy of the incident. A threat intelligence feed has correlated the source IP to a known financially motivated threat group. Understanding the strict definitions of threats, vulnerabilities, and attacks is crucial for accurate reporting.
Traffic & Logs
Question
How is an “attack” represented?