CND (312-38) Network Defense Simulation
Network defense extends beyond logical boundaries into the physical realm. This simulation teaches you how to align physical security controls with network defense-in-depth strategies to protect critical infrastructure from unauthorized physical access.
1 Network Scenario
You are reviewing the security posture of an organization's primary datacenter. The logical controls—including next-generation firewalls (NGFW), IDSs, and strict VLAN segmentation—are robust. However, during a recent internal Red Team assessment, an unauthorized individual bypassed the physical perimeter by simply walking closely behind an authorized network engineer. The CISO has demanded an immediate physical security upgrade to protect the core network equipment.
Network Access Control (NAC) via 802.1X
MFA required for all administrative panels
RFID Badge Readers at all doors
CCTV covering primary entrance
2 Traffic & Logs
Sample syslog from the Physical Access Control System (PACS) server:
Note: The alert highlights a disconnect between the logical authentication (one badge read) and the physical reality (two people entering).
3 Question
Justine has been tasked by her supervisor to ensure that the company's physical security is on the same level as their logical security measures. She installs video cameras at all entrances and exits and installs badge access points for all doors. The last item she wants to install is a method to prevent unauthorized people piggybacking employees. What should she install to prevent piggybacking?