incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecuritymediumBrute ForceCritical asset
Scenario

Brute-force on VPN gateway admin account — 1 successful login

A medium Cybersecurity scenario on Brute Force.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · brute-force-vpn-admin

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Brute-force detection patterns
  • Account lockout and IP-level containment
MITRE ATT&CKmitre-attack
  • Brute Force · Credential AccessT1110 · TA0006
    MappedHigh confidence

    Trains triage of repeated failed-authentication patterns against an exposed VPN endpoint.

MITRE D3FENDmitre-d3fend
  • Multi-factor AuthenticationD3-MFA
    MappedHigh confidence

    Trains the MFA-backed defense that resists password-only brute force.

  • Disable AccountD3-DI
    MappedMedium confidence

    Trains the conditional account-disable workflow on credential-attack signals.

NIST CSF 2.0nist-csf-2
  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detection of repeated failed-login telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains pattern recognition on authentication logs.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains source-IP and account-level containment.

CISA Cybersecurity Performance Goalscisa-cpg
  • Phishing-Resistant MFA2.E
    MappedHigh confidence

    Trains the MFA baseline that mitigates brute-force success.

  • Detection of Unsuccessful Logins2.Q
    MappedHigh confidence

    Trains the failed-login detection baseline the scenario exercises.

CIS Controls v8cis-controls
  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains the access-management control invoked under credential attack.

  • Audit Log ManagementControl 8
    MappedMedium confidence

    Trains the audit-log review the response depends on.