ExamRange
Home ExamRange Practice Tests

CND (312-38) Network Defense Simulation

Welcome to this scenario-based practice module. You will learn to identify invalid IP addressing schemes, a critical skill for auditing DHCP scopes, configuring edge firewall filtering, and identifying potential IP spoofing anomalies.

Network Scenario

You are conducting a security audit on a newly deployed IP Address Management (IPAM) solution and the edge firewall's Bogon filtering rules. A junior administrator has submitted a bulk import of DHCP scopes to automatically provision devices across multiple global sites.

Before approving the configuration, you run an automated validation script to ensure that none of the proposed subnets violate foundational IPv4 addressing standards. Assigning invalid addresses to endpoints will result in unroutable traffic and broken network communications.

Traffic & Logs

Output from the IPAM Scope Validation Audit Tool:

[INFO] Initiating RFC standard validation for proposed DHCP scopes... [INFO] Checking Scope 1: 10.0.0.0/8 -> STATUS: PASS (Valid Private Unicast) [INFO] Checking Scope 2: 172.16.0.0/16 -> STATUS: PASS (Valid Private Unicast) [INFO] Checking Scope 3: 192.168.1.0/24 -> STATUS: PASS (Valid Private Unicast) [WARN] Checking Scope 4: 224.0.1.0/24 -> STATUS: FAIL (Invalid host assignment) [WARN] Checking Scope 5: 240.0.0.0/4 -> STATUS: FAIL (Invalid host assignment) [!] ALERT: 2 scopes rejected. Administrator intervention required.

Note: The validation tool checks the leading bits of the first octet to determine the IPv4 class and its corresponding standard use case.

Question

Which of the following IP class addresses are not allotted to hosts?
Each correct answer represents a complete solution. Choose all that apply.
Hint: Think about the IP ranges beyond 223.255.255.255. These upper blocks are strictly reserved for multicast traffic and experimental research, meaning a standard workstation cannot be assigned an IP from these classes.

Expert Analysis

1. What is happening in the network

The junior administrator attempted to create DHCP scopes using IPv4 addresses from ranges strictly reserved for non-host purposes. The IPAM validation tool successfully caught this misconfiguration before endpoints were provisioned with unroutable IP addresses.

2. Identify Attack or Behavior

This scenario represents a configuration error, but from a defensive perspective, traffic originating from these IP classes on an internal network or arriving at the perimeter is highly suspicious. Attackers often use invalid source IPs (like Class E or Bogon space) to execute spoofed DoS attacks, bypass poorly configured ACLs, or obscure their origin.

3. Why correct answers are correct

B. Class D (224.0.0.0 to 239.255.255.255) is reserved exclusively for Multicast groups (e.g., routing protocols like OSPF/EIGRP, or streaming media). It is never assigned to a single host interface.

E. Class E (240.0.0.0 to 255.255.255.254) is reserved by the IETF for experimental purposes and future use. Standard operating systems will generally refuse to configure a Class E address on a network adapter.

4. Why others are wrong

A, C, and D are incorrect because Class A (1.0.0.0–126.255.255.255), Class B (128.0.0.0–191.255.255.255), and Class C (192.0.0.0–223.255.255.255) are the standard unicast address blocks specifically designed to be allotted to hosts, routers, and servers.

5. Defensive Action

Network defenders must implement "Bogon Filtering" at edge routers and firewalls. This means creating explicit ingress and egress drop rules for traffic sourced from or destined to Class D (unless specifically supporting multicast), Class E, loopback (127.0.0.0/8), and RFC 1918 private addresses arriving on the external public interface.

6. MINI LESSON: First Octet Rules

  • Class A: Leading bit 0 (0-127). Used for massive networks.
  • Class B: Leading bits 10 (128-191). Used for medium/large networks.
  • Class C: Leading bits 110 (192-223). Used for small networks.
  • Class D: Leading bits 1110 (224-239). Multicast only.
  • Class E: Leading bits 1111 (240-255). Experimental/Reserved.

Ready for more network analysis?

Improve your defensive mindset with full-length CND practice exams.

Explore more CND simulations