Before you can defend a network you have to speak the language of what's attacking it — this lesson builds the threat, vulnerability, and mitigation vocabulary that every later control in this domain assumes you already know.
Common Attack Types
A DDoS attack comes in three flavors you should be able to tell apart: volumetric floods that simply saturate bandwidth, protocol attacks like SYN floods that exhaust connection-state tables on a server or firewall, and application-layer floods (like an HTTP GET flood) that look like legitimate traffic but exhaust backend resources such as database connections. On-path attacks (the modern term for man-in-the-middle) place the attacker between two communicating parties — think ARP spoofing on a LAN segment, a rogue access point mimicking a trusted SSID, or SSL-stripping that silently downgrades HTTPS to HTTP. Credential reuse attacks (credential stuffing) take usernames and passwords leaked from one breach and replay them against other services, which is why unique passwords plus MFA defeat this class outright. BGP hijacking happens when an autonomous system announces IP prefixes it doesn't legitimately own, which can silently redirect, blackhole, or allow interception of traffic destined for the real owner — this has caused real internet outages and traffic-interception incidents. Social engineering — phishing, pretexting, baiting — bypasses technical controls entirely by manipulating a human into granting access or divulging information.
Underlying Vulnerabilities
Attacks succeed because a vulnerability exists underneath them. A zero-day is a flaw unknown to the vendor (and therefore unpatched) at the time it's exploited, which is why defense-in-depth matters even when patching is current. The OWASP Top 10 is the standard reference classification of the most critical web-application risks — injection flaws, broken access control, security misconfiguration, and so on — and it gives security teams a shared vocabulary for prioritizing application-layer risk. In practice, the single most common real-world entry point is simple misconfiguration: default credentials left in place, an overly permissive cloud storage bucket, a security group open to 0.0.0.0/0, or unpatched firmware sitting on a forgotten device.
Mitigation Practices and Frameworks
DLP (Data Loss Prevention) inspects outbound traffic and endpoints for sensitive data patterns (credit card numbers, health records) and blocks or flags exfiltration attempts. IPAM (IP Address Management) gives you an authoritative inventory of what's using every address on the network, which turns "who is this device and why is it talking to our database" from a mystery into a lookup. MITRE ATT&CK is a continuously updated knowledge base of real-world adversary tactics and techniques, used to map your existing defenses against how attackers actually operate rather than against a hypothetical threat. CIS Benchmarks are vendor- and platform-specific configuration standards (for a given OS, cloud provider, or network device) that translate "harden this system" into a concrete, auditable checklist.
Key Mechanics
- DDoS has three distinct attack surfaces: volumetric (bandwidth), protocol (state tables), and application-layer (backend resources) — each needs a different mitigation.
- Credential stuffing exploits password reuse across sites, not a flaw in any single system — MFA is the primary defense.
- BGP hijacking is a routing-layer threat, not a payload-based attack — it exploits trust between autonomous systems.
- MITRE ATT&CK organizes attacker behavior into tactics and techniques; CIS Benchmarks organize secure configuration into hardening checklists — they solve different problems.
- Misconfiguration, not zero-days, is the most statistically common root cause of real-world breaches.
Exam Tip: Don't confuse an on-path (MITM) attack with a DDoS attack — a scenario describing traffic being silently read or altered in transit is on-path; a scenario describing service becoming unavailable due to volume is DDoS.
Exam Tip: The exam may describe a scenario where a misconfigured router announces someone else's IP space — that's BGP hijacking, not DNS poisoning or ARP spoofing, even though the symptom (traffic going to the wrong place) can look similar.
Exam Tip: MITRE ATT&CK and CIS Benchmarks are both "frameworks" in casual speech, but the exam expects you to know ATT&CK maps attacker tactics/techniques while CIS Benchmarks map secure configuration baselines — they are not interchangeable answers.
Diagram
Worked example: A network engineer notices an unusual spike in outbound traffic to an unfamiliar IP range at 2 a.m., alongside several failed then successful admin logins from a new geographic location. Cross-referencing IPAM confirms the destination isn't a known internal or partner system, and the login pattern matches credential-stuffing behavior in the organization's MITRE ATT&CK-mapped playbook. The response team resets the compromised account's credentials, enforces MFA org-wide, and confirms DLP rules would have flagged the outbound data had it contained regulated data patterns — closing both the immediate access gap and the process gap that let it happen.