incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusionmediumNAC Bypass + PivotCritical asset
Scenario

Unauthorized host on prod VLAN — 802.1X bypass via printer MAC spoofing

A medium Cyber × Network Fusion scenario on NAC Bypass + Pivot.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · fusion-nac-bypass-pivot

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • NAC-edge triage discipline
  • Edge-to-internal scoping workflow
MITRE ATT&CKmitre-attack
  • Valid Accounts · Initial AccessT1078 · TA0001
    MappedHigh confidence

    Trains triage when NAC-binding posture is circumvented.

  • Remote Services · Lateral MovementT1021 · TA0008
    MappedMedium confidence

    Trains internal scoping after NAC bypass.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains east-west visibility for unexpected access patterns.

  • User Account PermissionsD3-UAP
    MappedMedium confidence

    Trains the permission-scoping discipline.

NIST CSF 2.0nist-csf-2
  • Access Control · ProtectPR.AC · PR
    MappedHigh confidence

    Trains the access-control baseline at the edge.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains the monitoring baseline.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains NAC-bypass triage discipline.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains port-level containment and isolation workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Asset Inventory1.A
    MappedHigh confidence

    Trains the asset-inventory baseline.

  • Document Network Topology2.M
    MappedHigh confidence

    Trains the topology baseline.

CIS Controls v8cis-controls
  • Inventory and Control of Enterprise AssetsControl 1
    MappedHigh confidence

    Trains the asset-inventory control.

  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains the access-management control.