2.0 - Basic Network Security Concepts Flashcards
(28 cards)
SAFE stands for…
Security Access For Everyone
What’s a PIN?
Place In (your) Network
A forward proxy services requests from _____.
Internal users
A reverse proxy services requests from ____.
External users on the internet
True or false: reverse proxy servers can be the termination point for SSL/TLS connections.
True
What is Cisco WSA?
Web Security Appliance, either a hardware or software proxy server.
An IDS is not placed inline with the flow of traffic. Therefore…
it does not prevent malicious activity, merely detects it.
An IDS/IPS installed on a server would be considered _____, whereas an IDS/IPS placed in front of a firewall would be considered _____.
host-based, network-based
What is signature-based detection?
Using a database of known attack signatures or patterns to identify malicious activity.
What are secure domains?
Concepts - management, security intelligence, compliance, segmentation, threat defense, and secure services.
SAFE key concept, p. 103
AES-256 is a/an _______ algorithm.
encryption
SHA-256 is a/an _______ algorithm.
hashing
When a VPN sequences the packets in the flow, this is an example of _____.
anti-replay protection
Name two secure tunnel protocols.
IPSec and SSL/TLS
What is Cisco AnyConnect?
Host-based remote-access VPN software. Also known as Cisco Secure Client.
What does ESP provide that AH does not?
Encryption
Which protocol is used in IPSec over the internet, AH or ESP?
ESP
Explain the fundamental difference between IPSec tunnel mode and transport mode.
In transport mode, the original IP header is left unencrypted. In tunnel mode, it is encrypted and a new IP header is added.
A device which “monitors and controls incoming and outgoing network traffic based on predefined security rules and policies” is a _____.
firewall
Cisco Firepower is what?
a next-generation firewall
AMP, a feature of next-gen firewalls, stands for what?
Advanced Malware Protection
“C2” refers to what?
Command and Control, a hacking term
What is Cisco ISE and what service does it provide?
Identity Services Engine, and it provides network access control (NAC) services
What is Cisco TrustSec?
a security framework that enables group-based access control