Network Threats and Attacks

Study ISC2 CC network threats and attacks: DDoS, virus, worm, Trojan, MITM, side-channel, IDS, HIDS, NIDS, IPS, firewalls, and antivirus.

Network attack questions test recognition plus response. The strongest answer usually identifies the attack pattern and chooses whether prevention, detection, containment, or recovery is needed.

Attack recognition

Threat Basic signal
DDoS service overwhelmed by traffic or requests
Virus malware that attaches to files/programs and spreads with user/system action
Worm self-propagating malware
Trojan malicious function hidden inside something that appears legitimate
MITM attacker intercepts or manipulates communications
Side-channel attacker infers secrets from indirect signals such as timing or power behavior

Detection and prevention controls

Control Role
IDS detects suspicious activity
HIDS detects on hosts
NIDS detects on networks
IPS can block or prevent suspicious activity
Firewall filters traffic by rule
Antivirus / antimalware detects or blocks known/suspicious malware
Scan identifies vulnerabilities or exposures

AI-security angle

The current outline notes AI-powered monitoring and automated threats. At CC level, remember: AI-assisted alerts still need human validation, escalation, and evidence.

Common traps

  • IDS detects; IPS can prevent/block.
  • Antivirus does not replace patching, least privilege, backups, and awareness.
  • DDoS is primarily an availability attack.
  • MITM is not fixed by user training alone; secure protocols, certificate validation, and network protections matter.
Revised on Monday, June 15, 2026