incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Network Engineeringextremely-hardSegmentation Failure (Suspected Intrusion)Critical asset
Scenario

Segmentation drift found during a suspected intrusion — VLAN/ACL gap with a monitoring blind spot

A extremely-hard Network Engineering scenario on Segmentation Failure (Suspected Intrusion).

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · network-segmentation-failure-intrusion

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Evidence-preserving segmentation restoration
  • Joint network+SOC triage under ambiguity
MITRE ATT&CKmitre-attack
  • Exploitation of Remote Services · Lateral MovementT1210 · TA0008
    PartialLow confidence

    Trains defensive reasoning about an east-west path opened by segmentation drift.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedMedium confidence

    Trains the east-west visibility posture for segmentation review.

NIST CSF 2.0nist-csf-2
  • Identity Management and Access Control · ProtectPR.AC · PR
    MappedHigh confidence

    Trains the network-segmentation access-control baseline.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detection reasoning when monitoring has a coverage gap.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains blast-radius reasoning with incomplete evidence (fault vs breach).

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains evidence-preserving, scoped restoration of segmentation.

CISA Cybersecurity Performance Goalscisa-cpg
  • Network Segmentation2.X
    MappedHigh confidence

    Trains the segmentation baseline the scenario exercises.

  • Document Network Topology2.M
    MappedMedium confidence

    Trains the topology baseline behind blast-radius estimation.

CIS Controls v8cis-controls
  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains the segmentation-management control.

  • Network Monitoring and DefenseControl 13
    MappedMedium confidence

    Trains the monitoring discipline exposed by the collector gap.