CND (312-38) Network Defense Simulation
Network Scenario
You are reviewing edge firewall drops and internal NetFlow telemetry. You notice two distinct anomalies: First, an external entity is sending TCP SYN packets into your network originating from an IP address range that should never exist on the public internet. Second, a standard endpoint in your internal marketing subnet is generating localized UDP traffic destined for an address range normally reserved for routing protocol exchanges.
To accurately classify these events as either misconfigurations or active attacks (such as DDoS backscatter or internal reconnaissance), you must understand the architecture of IPv4 address classes.
Traffic & Logs
Question
Expert Analysis
1. What is happening in the network
The firewall is dropping traffic from 240.15.2.10, an address residing in the Class E experimental range. Meanwhile, the IDS is alerting on an internal endpoint (10.10.5.55) trying to communicate with 224.0.0.10, a Class D multicast address typically used by the EIGRP routing protocol.
2. Identify attack or behavior
The ingress traffic from the Class E space is heavily spoofed; attackers often forge source IPs to launch reflection/amplification DDoS attacks or obscure their origins. The internal traffic to the Class D space from a non-router device is highly suspicious and indicates either network misconfiguration, a routing protocol injection attempt, or a compromised host performing network topology mapping.
3. Why correct answers are correct
Class D (224.0.0.0 to 239.255.255.255) is explicitly reserved for Multicast groups (sending data to multiple destinations simultaneously).
Class E (240.0.0.0 to 255.255.255.255) is reserved by the IETF for experimental use. Neither class can be assigned as a standard host IP address.
4. Why others are wrong
- Class A: (1.0.0.0 to 126.0.0.0) is designated for unicast host assignments (large networks).
- Class B (B-): (128.0.0.0 to 191.255.0.0) is designated for unicast host assignments (medium networks).
5. Defensive action
Implement strict Bogon Filtering (ingress and egress anti-spoofing filters) at network boundaries. A bogon is a bogus (fake) IP address of a computer network, including Class D, Class E, loopback, and unallocated spaces. Drop these at the edge. Internally, implement IGMP snooping and strictly control which switch ports are authorized to participate in routing protocol multicast exchanges.
A successful Network Defender must instantly recognize abnormal IP allocations to spot spoofing and malware lateral movement:
- Class A, B, C: Unicast (One-to-One). Host assignable.
- Class D: Multicast (One-to-Many). E.g., OSPF (224.0.0.5), RIPv2 (224.0.0.9). Should only originate from authorized routers or specific multicast servers.
- Class E: Experimental. Should never be seen in production routing tables or as valid source/destination traffic. Drop immediately.
Explore more CND simulations to sharpen your network defense skills.
View Practice Tests