Recognizing network attacks by their symptoms and matching them to effective mitigations is a core CISSP skill. The goal here is defensive understanding: what the attack does, what it looks like in your logs and monitoring, and how to prevent or limit it. The exam will not ask you to run an attack, but it will describe one and ask for the best control. Most network attacks exploit one of three things: finite capacity, protocols that trust unverified addresses, or users and systems that do not check who they are talking to.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.