Módulo 05 - Network Architecture Flashcards
Módulo 05 (130 cards)
Define:
Network infraestructure
It’s the media, appliances and protocols that support connectivity.
Acronym:
OSI
Open System Interconnection
What are the OSI model layers?
- Physical
- Data-link
- Network
- Transport
- Session
- Presentation
- Application
For CompTIA, consider only 1, 2, 3, 4 and 7
Acronym:
MAC
Media Access Control
Define:
MAC Address
Layer 2 component, attached to the hosts.
Used as an identifier, and is a 48-bit string
Types of node in a network
Intermediary nodes => Forward traffic of a network to other hosts
Host nodes => Initiates the communication in a network
What are the OSI layers that refers to:
- Switches
- Routers
- Transport Protocols
- Layer 2, because it uses MAC addresses
- Layer 3, because it uses IP address
- Layer 4, because it uses network protocols such as TCP, or UDP
In network terms, define what would be:
- Preventative controls
- Detective controls
- Preventative, detective, and corrective controls
- Placed at the border of a network, such as firewalls or Load Balancers
- Implemented to monitor the traffic, generates alerts in malicious traffic
- Installed on hosts, such EDR
What is a passive security control?
A control that operates without requiring any client configuration
What is an active security control?
A control requiring credentials, access permissions, and interaction with target hosts, often involving agent software or gateway configuration.
What does “inline” mean for a security device?
A device deployed within the cable path, without requiring changes to IP or routing topology, and typically without MAC or IP addresses.
What are two methods for deploying network traffic sniffing controls?
- SPAN (switched port analyzer)/mirror port.
- Test access point (TAP).
What is a SPAN or mirror port?
A switch-configured port that copies frames from other ports for monitoring but may drop frames under heavy load.
What is a TAP (test access point)?
A device inline with network cabling that physically copies signals to a monitor port without logic-based decisions.
What is a fail-open and fail-close mode?
Fail-open is a failure state where access is not blocked, whether fail-close is where access is blocked
Acronym:
SPAN
Switched Port Analyzer
What is the difference between TAP and SPAN regarding reliability?
TAP reliably copies all frames, while SPAN may miss frames with errors or drop them under heavy load.
Define:
Proxy server
Acts as an intermediary for clients, providing traffic management, anonymity, content filtering, and caching.
Define:
Jump server
Hardened server controlling access to isolated systems, enhancing security.
Define:
Load balancer
Distributes network traffic across servers, provides fault tolerance, and may include WAF for attack protection.
List:
Types of load balancers
- Layer 4 (Transport layer decisions).
- Layer 7 (Application-level data decisions).
Define:
Sensor
A packet sniffer used to capture traffic, often feeding an IDS for malicious traffic detection.
Define:
IDS
Intrusion Detection System identifies threats without blocking traffic.
Define:
All-in-one security appliance
Device combining functions like firewall, IDS, IPS, URL filtering, and spam filtering into one.