CND (312-38) Network Defense Simulation
Welcome to this scenario-based practice module. You will learn to identify invalid IP addressing schemes, a critical skill for auditing DHCP scopes, configuring edge firewall filtering, and identifying potential IP spoofing anomalies.
Network Scenario
You are conducting a security audit on a newly deployed IP Address Management (IPAM) solution and the edge firewall's Bogon filtering rules. A junior administrator has submitted a bulk import of DHCP scopes to automatically provision devices across multiple global sites.
Before approving the configuration, you run an automated validation script to ensure that none of the proposed subnets violate foundational IPv4 addressing standards. Assigning invalid addresses to endpoints will result in unroutable traffic and broken network communications.
Traffic & Logs
Output from the IPAM Scope Validation Audit Tool:
Note: The validation tool checks the leading bits of the first octet to determine the IPv4 class and its corresponding standard use case.
Question
Each correct answer represents a complete solution. Choose all that apply.
Expert Analysis
1. What is happening in the network
The junior administrator attempted to create DHCP scopes using IPv4 addresses from ranges strictly reserved for non-host purposes. The IPAM validation tool successfully caught this misconfiguration before endpoints were provisioned with unroutable IP addresses.
2. Identify Attack or Behavior
This scenario represents a configuration error, but from a defensive perspective, traffic originating from these IP classes on an internal network or arriving at the perimeter is highly suspicious. Attackers often use invalid source IPs (like Class E or Bogon space) to execute spoofed DoS attacks, bypass poorly configured ACLs, or obscure their origin.
3. Why correct answers are correct
B. Class D (224.0.0.0 to 239.255.255.255) is reserved exclusively for Multicast groups (e.g., routing protocols like OSPF/EIGRP, or streaming media). It is never assigned to a single host interface.
E. Class E (240.0.0.0 to 255.255.255.254) is reserved by the IETF for experimental purposes and future use. Standard operating systems will generally refuse to configure a Class E address on a network adapter.
4. Why others are wrong
A, C, and D are incorrect because Class A (1.0.0.0–126.255.255.255), Class B (128.0.0.0–191.255.255.255), and Class C (192.0.0.0–223.255.255.255) are the standard unicast address blocks specifically designed to be allotted to hosts, routers, and servers.
5. Defensive Action
Network defenders must implement "Bogon Filtering" at edge routers and firewalls. This means creating explicit ingress and egress drop rules for traffic sourced from or destined to Class D (unless specifically supporting multicast), Class E, loopback (127.0.0.0/8), and RFC 1918 private addresses arriving on the external public interface.
6. MINI LESSON: First Octet Rules
- Class A: Leading bit
0(0-127). Used for massive networks. - Class B: Leading bits
10(128-191). Used for medium/large networks. - Class C: Leading bits
110(192-223). Used for small networks. - Class D: Leading bits
1110(224-239). Multicast only. - Class E: Leading bits
1111(240-255). Experimental/Reserved.
Ready for more network analysis?
Improve your defensive mindset with full-length CND practice exams.
Explore more CND simulations