incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Network EngineeringhardBGP LeakCritical asset
Scenario

Customer prefix 203.0.113.0/22 announced from unintended AS — suspected BGP route leak

A hard Network Engineering scenario on BGP Leak.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · network-bgp-route-leak

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • BGP path-change triage
  • Coordinated peer-rollback discipline
MITRE ATT&CKmitre-attack
  • Data Manipulation · ImpactT1565 · TA0040
    PartialLow confidence

    Trains defensive reasoning when a routing change has external impact.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedMedium confidence

    Trains the traffic-visibility posture for path-change diagnosis.

NIST CSF 2.0nist-csf-2
  • Protective Technology · ProtectPR.PT · PR
    MappedHigh confidence

    Trains the protective-technology baseline behind BGP policy.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains the monitoring discipline for routing telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains structured triage of unexpected BGP path changes.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedMedium confidence

    Trains coordinated peer-level rollback and containment.

CISA Cybersecurity Performance Goalscisa-cpg
  • Document Network Topology2.M
    MappedHigh confidence

    Trains the topology baseline.

  • Detecting Relevant Threats and TTPs3.A
    MappedMedium confidence

    Trains the routing-anomaly detection baseline.

CIS Controls v8cis-controls
  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains the network-management control.

  • Network Monitoring and DefenseControl 13
    MappedMedium confidence

    Trains the monitoring discipline behind routing review.