incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Network Engineeringextremely-hardVPN/Firewall Policy RegressionCritical asset
Scenario

After a firewall/VPN policy push, tunnels drop intermittently and an unexpected outbound flow appears

A extremely-hard Network Engineering scenario on VPN/Firewall Policy Regression.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · network-vpn-firewall-policy-regression

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Regression-vs-exfil triage after a policy push
  • Containment-vs-availability decision making
MITRE ATT&CKmitre-attack
  • Exfiltration Over Alternative Protocol · ExfiltrationT1048 · TA0010
    PartialLow confidence

    Trains defensive triage of an ambiguous outbound flow as possible exfiltration.

MITRE D3FENDmitre-d3fend
  • Outbound Traffic FilteringD3-OTF
    MappedMedium confidence

    Trains scoped outbound filtering instead of a blanket block.

NIST CSF 2.0nist-csf-2
  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detection of a post-change outbound flow against baseline.

  • Mitigation · RespondRS.MI · RS
    MappedHigh confidence

    Trains containment-vs-availability mitigation reasoning.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains separating a benign policy regression from a possible exfil indicator.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains scoped containment that preserves service and firewall/VPN state.

CISA Cybersecurity Performance Goalscisa-cpg
  • Network Segmentation2.X
    PartialLow confidence

    Trains policy-boundary reasoning where a reordered rule widened access.

  • Log Collection2.T
    MappedHigh confidence

    Trains the central-logging baseline the rotated buffer exposes.

CIS Controls v8cis-controls
  • Secure Configuration of Enterprise Assets and SoftwareControl 4
    MappedHigh confidence

    Trains the firewall-rule-order configuration discipline.

  • Network Monitoring and DefenseControl 13
    MappedMedium confidence

    Trains the outbound-flow monitoring the triage depends on.