In this simulation, you will analyze a network scenario involving user-targeted social engineering. You will learn to differentiate between network-level attacks and application/social layer threats.

CND (312-38) Network Defense Simulation

Network Scenario

You are monitoring the corporate LAN of a medium-sized enterprise. The network architecture includes an Edge Firewall, a DMZ housing a Mail Gateway, and internal user VLANs. Recently, several users in the Accounting department reported receiving internal-looking emails requesting them to verify their credentials on a "New Employee Portal."

Internal security policy mandates Multi-Factor Authentication (MFA), but the logs suggest some external attempts are originating from IP addresses not associated with the company's VPN.

Traffic & Logs

[2023-10-24 09:12:04] IDS ALERT: Possible SMTP Spoofing Detected from 192.168.4.12
[2023-10-24 09:14:22] FIREWALL: BLOCK TCP 203.0.113.45 -> 10.0.5.22:80 (Policy: Default Deny)
[2023-10-24 09:15:10] MAIL_GATEWAY: Inbound Email [Subject: ACTION REQUIRED: Update Password] To: finance_dept@corp.com From: admin@corp-hr-portal.net [External Sender]
[2023-10-24 09:18:45] HTTP_PROXY_LOG: User 10.0.10.55 -> GET http://corp-hr-portal.net/login.php (Categorized: Suspicious/Uncategorized)
[2023-10-24 09:20:12] DNS_QUERY: 10.0.10.55 queried 'corp-hr-portal.net' -> Resolved to 203.0.113.88

Question

Which of the following is a type of scam that entices a user to disclose personal information?

Expert Analysis

Explore more CND simulations

Practice More at ExamRange