CND (312-38) Network Defense Simulation
In this module, you will analyze the implementation of deception systems within an enterprise DMZ. You will learn to distinguish between different honeypot architectures and their roles in active defense.
01. Network Scenario
Your organization has deployed a series of decoy systems in a isolated VLAN (VLAN 99) to detect and study lateral movement within the network. These systems mimic high-value targets: a Windows File Server, an Ubuntu Web Server, and a SQL Database instance.
02. Traffic & Logs
2023-10-27T14:22:03.112 [IDS-ALERT] Incoming Probe detected on VLAN 99
2023-10-27T14:22:05.889 [HONEYPOT-SYS] Interaction detected on Node B (HTTP GET /admin)
2023-10-27T14:22:08.001 [COLLECTOR] Aggregating multi-node interaction data for analysis...
03. Question
Which of the following systems is formed by a group of honeypots?
04. Expert Analysis
1. What is happening in the network
The network scenario describes a deliberate deployment of multiple decoy systems. Traffic logs show that an internal or external actor is probing these specific IP addresses. Since these are "honeypots," any interaction is inherently suspicious as no legitimate user should be accessing these services.
2. Identify attack or behavior
The behavior identified is Network Enumeration and Scanning. The actor is testing various ports (SMB 445, HTTP 80) across the decoy range. By grouping these honeypots, the defender can track how the attacker moves from one node to another.
3. Why the correct answer is correct
A Honeynet is a high-interaction network of two or more honeypots. It is designed to represent a real-world network segment. Unlike a single honeypot, a honeynet allows for the monitoring of an attacker's lateral movement and complex multi-stage attack patterns.
4. Why others are wrong
- Research Honeypot: This refers to the *purpose* (gathering intelligence on attacker tactics) rather than the *structure*.
- Honeyfarm: This is a centralized collection of honeypots and data redirected from many different locations, often for large-scale analysis, rather than the architectural term for a group of honeypots in a network context.
- Production Honeypot: This refers to the *deployment goal* (distracting attackers from real production servers and providing early warning) rather than the architectural grouping.
Mini Lesson: Deception Architecture
In CND, we categorize honeypots by Interaction Level (Low-interaction vs. High-interaction) and Usage (Production vs. Research). When we connect these decoys to simulate a legitimate network environment with routers, switches, and servers, it evolves into a Honeynet. This structure uses "Honeywalls" to control data flow, ensuring that if a honeypot is compromised, it cannot be used to attack the real production network.