ExamRange

CND (312-38) Network Defense Simulation

In this module, you will analyze the implementation of deception systems within an enterprise DMZ. You will learn to distinguish between different honeypot architectures and their roles in active defense.

01. Network Scenario

Your organization has deployed a series of decoy systems in a isolated VLAN (VLAN 99) to detect and study lateral movement within the network. These systems mimic high-value targets: a Windows File Server, an Ubuntu Web Server, and a SQL Database instance.

Node A (Decoy)
172.16.99.10 (SMB)
Node B (Decoy)
172.16.99.20 (HTTP)
Node C (Decoy)
172.16.99.30 (MSSQL)

02. Traffic & Logs

[SNORT ALERT] 1:2010935:3 - ET SCAN Potential SSH Scan
2023-10-27T14:22:01.034 [FW-LOG] DENY TCP 10.0.5.15:44321 -> 172.16.99.10:445 [Flags: S]
2023-10-27T14:22:03.112 [IDS-ALERT] Incoming Probe detected on VLAN 99
2023-10-27T14:22:05.889 [HONEYPOT-SYS] Interaction detected on Node B (HTTP GET /admin)
2023-10-27T14:22:08.001 [COLLECTOR] Aggregating multi-node interaction data for analysis...
# Data Source: Centralized Deception Management Console

03. Question

Which of the following systems is formed by a group of honeypots?