incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusioneasyRogue DHCP MITMHigh asset
Scenario

Guest VLAN: rogue DHCP redirecting users to a fake SSO portal

A easy Cyber × Network Fusion scenario on Rogue DHCP MITM.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · fusion-rogue-dhcp-mitm

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Layer-2 MITM triage
  • Access-port isolation discipline
MITRE ATT&CKmitre-attack
  • Adversary-in-the-Middle · Credential AccessT1557 · TA0006
    MappedHigh confidence

    Trains triage of MITM-style redirection on a layer-2 segment.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains layer-2 visibility reasoning for redirection symptoms.

  • Inbound Connection FilteringD3-IBCA
    MappedMedium confidence

    Trains the inbound-filtering posture (DHCP snooping).

NIST CSF 2.0nist-csf-2
  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains the monitoring discipline on access-layer telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains triage of MITM symptoms.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains source-port isolation workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Document Network Topology2.M
    MappedHigh confidence

    Trains the topology baseline.

  • Detecting Relevant Threats and TTPs3.A
    MappedMedium confidence

    Trains the threat-detection baseline.

CIS Controls v8cis-controls
  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains the network-management control.

  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the monitoring control the scenario exercises.