Four words that are easy to mix up
| Term | Meaning | Example |
|---|---|---|
| Threat | Someone or something that could cause harm | An attacker scanning the internet for exposed routers |
| Vulnerability | A weakness that could be used | A router reachable from the internet with Telnet enabled |
| Exploit | The method or tool that uses the weakness | Capturing the Telnet password in clear text, then logging in |
| Mitigation | A control that reduces the risk | SSH only, an ACL on the VTY lines, strong passwords |
Risk only exists where a threat meets a vulnerability. A server with an unpatched bug that nothing can reach is a lower risk than a patched server with a weak administrator password on the internet.
Common attacks and the CCNA mitigations
| Attack | Vulnerability it uses | Mitigation in this course |
|---|---|---|
| MAC flooding | A switch's MAC table has a limited size | Port security |
| Rogue DHCP server | Clients accept the first DHCP offer | DHCP snooping |
| ARP spoofing (man in the middle) | ARP has no authentication | Dynamic ARP Inspection |
| Password guessing, sniffing | Weak passwords, Telnet | Secrets, SSH, login limits and AAA |
| Unwanted access between networks | Routers forward everything by default | ACLs |
| Eavesdropping across the internet | Traffic crosses networks you don't control | IPsec VPNs |
| Phishing, social engineering | People trust messages that look official | User awareness and training (below), MFA |
| Denial of service | Limited bandwidth or processing | Rate limits, filtering at the provider, spare capacity |
A security program: people and places, too
A security program is the organisation's plan for staying safe. The CCNA names three parts that are not configuration:
- User awareness. Everyone knows the common tricks: phishing emails, fake login pages, phone calls asking for passwords, USB sticks left in the car park. Simulated phishing campaigns test it.
- Training. Deeper, role-based teaching: network staff learn secure configuration and incident response; help-desk staff learn how to verify who is calling before resetting a password.
- Physical access control. Locked wiring closets and data centres, badge readers, visitor escorts and logs, cameras. Anyone who can reach a console port or unplug a cable can bypass most network controls.
💡 In simple terms: the firewall rules don't help if someone holds the door open for a stranger with a laptop.
Troubleshooting exercise: what failed?
A visitor waiting in a meeting room plugs a laptop into the wall port, gets an address on the staff VLAN and reaches internal file shares. Later that day, a staff member reports an email asking them to "re-enter your password" on a page that looked like the company portal.
Show the analysis
- Vulnerabilities: a live port in the staff VLAN in a public room; no check of who connects; staff not recognising phishing.
- Exploits: plugging in to an open port; a fake login page.
- Technical mitigations: shut unused ports or put them in an unused VLAN, port security, 802.1X with RADIUS, MFA so a stolen password isn't enough.
- Program mitigations: visitor escort policy (physical access), phishing awareness for all staff, training for the help desk on handling the reports.
Check yourself
A router still has Telnet enabled on its VTY lines. Which term describes that?
A tool captures the clear-text Telnet password and logs in with it. Which term is that?
Which is an example of physical access control?
Help-desk staff learn to confirm a caller's identity before resetting a password. Which part of a security program is this?
Learn more: Network Security BasicsPort Security