Routelearn.net
Course menu

Course 13: Security FundamentalsLesson 1.1 (1 of 10 in this course)90 of 104 in the CCNA series

Threats, vulnerabilities and security programs

Threat, vulnerability, exploit and mitigation in real examples, and the people side of security: awareness, training and physical access.

Intermediate · 8 min read

After this lesson, you can tell a threat, a vulnerability, an exploit and a mitigation apart in a real incident, and name the parts of a security program that aren't technology.

Vulnerability is a weakness in a system, its configuration or the way people use it that could be used to break its confidentiality, integrity or availability. A threat is something that could take advantage of it, an exploit is the actual method used, and a mitigation reduces the chance or the impact.

In simple terms: A vulnerability is an unlocked window. A threat is a burglar who might come by. The exploit is climbing through the window. The mitigation is the lock.

Four words that are easy to mix up

TermMeaningExample
ThreatSomeone or something that could cause harmAn attacker scanning the internet for exposed routers
VulnerabilityA weakness that could be usedA router reachable from the internet with Telnet enabled
ExploitThe method or tool that uses the weaknessCapturing the Telnet password in clear text, then logging in
MitigationA control that reduces the riskSSH only, an ACL on the VTY lines, strong passwords

Risk only exists where a threat meets a vulnerability. A server with an unpatched bug that nothing can reach is a lower risk than a patched server with a weak administrator password on the internet.

Common attacks and the CCNA mitigations

AttackVulnerability it usesMitigation in this course
MAC floodingA switch's MAC table has a limited sizePort security
Rogue DHCP serverClients accept the first DHCP offerDHCP snooping
ARP spoofing (man in the middle)ARP has no authenticationDynamic ARP Inspection
Password guessing, sniffingWeak passwords, TelnetSecrets, SSH, login limits and AAA
Unwanted access between networksRouters forward everything by defaultACLs
Eavesdropping across the internetTraffic crosses networks you don't controlIPsec VPNs
Phishing, social engineeringPeople trust messages that look officialUser awareness and training (below), MFA
Denial of serviceLimited bandwidth or processingRate limits, filtering at the provider, spare capacity

A security program: people and places, too

A security program is the organisation's plan for staying safe. The CCNA names three parts that are not configuration:

  • User awareness. Everyone knows the common tricks: phishing emails, fake login pages, phone calls asking for passwords, USB sticks left in the car park. Simulated phishing campaigns test it.
  • Training. Deeper, role-based teaching: network staff learn secure configuration and incident response; help-desk staff learn how to verify who is calling before resetting a password.
  • Physical access control. Locked wiring closets and data centres, badge readers, visitor escorts and logs, cameras. Anyone who can reach a console port or unplug a cable can bypass most network controls.

💡 In simple terms: the firewall rules don't help if someone holds the door open for a stranger with a laptop.

Troubleshooting exercise: what failed?

A visitor waiting in a meeting room plugs a laptop into the wall port, gets an address on the staff VLAN and reaches internal file shares. Later that day, a staff member reports an email asking them to "re-enter your password" on a page that looked like the company portal.

Show the analysis
  • Vulnerabilities: a live port in the staff VLAN in a public room; no check of who connects; staff not recognising phishing.
  • Exploits: plugging in to an open port; a fake login page.
  • Technical mitigations: shut unused ports or put them in an unused VLAN, port security, 802.1X with RADIUS, MFA so a stolen password isn't enough.
  • Program mitigations: visitor escort policy (physical access), phishing awareness for all staff, training for the help desk on handling the reports.

Check yourself

Predict · scenario 1

A router still has Telnet enabled on its VTY lines. Which term describes that?

Predict · scenario 2

A tool captures the clear-text Telnet password and logs in with it. Which term is that?

Predict · scenario 3

Which is an example of physical access control?

Predict · scenario 4

Help-desk staff learn to confirm a caller's identity before resetting a password. Which part of a security program is this?

Learn more: Network Security BasicsPort Security

FAQ

Is a vulnerability always a software bug?
No. A default password, an unused switch port left in an active VLAN, Telnet instead of SSH, or a staff member who doesn't recognise phishing are all vulnerabilities. Many incidents use configuration and people weaknesses rather than code bugs.
Why does the CCNA include training and physical security?
Because network controls can be bypassed by people. Someone with physical access to a router's console port, or who tricks a user into giving away a password, can get past well-configured ACLs and firewalls. A security program covers people and places as well as devices.