In this simulation, you will analyze fundamental IPv4 routing concepts and identify anomalous network traffic involving reserved IP address spaces. You will learn to recognize bogus IP allocations and understand the defensive posture required to implement robust bogon filtering.

CND (312-38) Network Defense Simulation

Network Scenario

You are reviewing edge firewall drops and internal NetFlow telemetry. You notice two distinct anomalies: First, an external entity is sending TCP SYN packets into your network originating from an IP address range that should never exist on the public internet. Second, a standard endpoint in your internal marketing subnet is generating localized UDP traffic destined for an address range normally reserved for routing protocol exchanges.

To accurately classify these events as either misconfigurations or active attacks (such as DDoS backscatter or internal reconnaissance), you must understand the architecture of IPv4 address classes.

Traffic & Logs

[FIREWALL] INGRESS_DROP: SRC: 240.15.2.10 DST: 198.51.100.45 PROTO: TCP DPORT: 443 REASON: ACL_BOGON_BLOCK [IDS/IPS] ALERT ENABLED: SID 2010111 - ET SCAN Suspicious Routing Protocol Multicast from Endpoint SRC: 10.10.5.55 DST: 224.0.0.10 PROTO: UDP DPORT: 88 MESSAGE: "Potential EIGRP Reconnaissance"

Question

Which of the following IP addresses is not reserved for the hosts? Each correct answer represents a complete solution. Choose all that apply.
Hint: Host addresses belong to unicast networks (Classes A, B, and C). Which classes are reserved for Multicast and Experimental purposes? (Select multiple)

Expert Analysis

1. What is happening in the network

The firewall is dropping traffic from 240.15.2.10, an address residing in the Class E experimental range. Meanwhile, the IDS is alerting on an internal endpoint (10.10.5.55) trying to communicate with 224.0.0.10, a Class D multicast address typically used by the EIGRP routing protocol.

2. Identify attack or behavior

The ingress traffic from the Class E space is heavily spoofed; attackers often forge source IPs to launch reflection/amplification DDoS attacks or obscure their origins. The internal traffic to the Class D space from a non-router device is highly suspicious and indicates either network misconfiguration, a routing protocol injection attempt, or a compromised host performing network topology mapping.

3. Why correct answers are correct

Class D (224.0.0.0 to 239.255.255.255) is explicitly reserved for Multicast groups (sending data to multiple destinations simultaneously).
Class E (240.0.0.0 to 255.255.255.255) is reserved by the IETF for experimental use. Neither class can be assigned as a standard host IP address.

4. Why others are wrong

5. Defensive action

Implement strict Bogon Filtering (ingress and egress anti-spoofing filters) at network boundaries. A bogon is a bogus (fake) IP address of a computer network, including Class D, Class E, loopback, and unallocated spaces. Drop these at the edge. Internally, implement IGMP snooping and strictly control which switch ports are authorized to participate in routing protocol multicast exchanges.

MINI LESSON: The IPv4 Address Space Map

A successful Network Defender must instantly recognize abnormal IP allocations to spot spoofing and malware lateral movement:

  • Class A, B, C: Unicast (One-to-One). Host assignable.
  • Class D: Multicast (One-to-Many). E.g., OSPF (224.0.0.5), RIPv2 (224.0.0.9). Should only originate from authorized routers or specific multicast servers.
  • Class E: Experimental. Should never be seen in production routing tables or as valid source/destination traffic. Drop immediately.

Explore more CND simulations to sharpen your network defense skills.

View Practice Tests