Securing Networks Flashcards

1
Q

What is a UTM?

A

Unified threat management.

An all in 1 device employ for network security. Provides a wide range of services like:

IPS/IDS
Firewall
Content Filtering
NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a firewall?

A

A device that filters traffic as it moves from an area of your network to another area of you network or to an area outside your network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a stateless firewall?

A

Does NOT keep track of session information. Source destination and port#.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a stateful Firewall?

A

Does keep track of session information. Maintain aware of active connections. It sequences everything also. It can make a more inform decision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an application based firewall?

A

Tracks sessions information. They track on Layer 7 and user behavior.

Ex. Guardicore

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a screened subnet (DMZ) topology?

A

Is the buffer zone between the internet and private network. Your publicly accessible services are places here. You can control the traffic to protect your connection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Bastion Host / Jump Box ?

A

A device we setup in the DMZ zone to enhance remote access security.

You have to harden your jump box to prevent any compromise activity.

You make an SSH connection to the jumpbox then to the internal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an IDS/NIDS system?

A

Intrusion detection system is a device that can alert you of any anomalies on your network for you to react. Traffic already reached the destination.

Its job is to alert but not react

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is an IPS/NIPS system?

A

Intrusion prevention system. It will alert you of any issues and prevent/react. It has to be inline on the traffic.

Signature based / stateful protocol analysis /

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a proxy server?

A

An device that sits between a client that is requesting a resource and a server that is providing a resource.

Features:
It can mask the client from the server

Reverse Proxy - is from client to server
Maintain session persistence with the back end.
Load balancers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a VLAN?

A

Logical segmentation on the same physical switch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is IPSec?

A

A framework that provides the means of creating a secure trusted IP tunnel over untrusted networks

Confidentiality with encryption

Integrity with hashing

Authentication with RSA

Anti-replay with sequencing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Spanning-tree protocol used for?

A

Prevent layer 2 loop from crashing our L2 network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is BPDU guard?

A

Prevent rogue devices from modifying our STP topology by sending bogus BPDU into our network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are storm control used?

A

Rate limit the number of broadcast, multicast or unicast packets to prevent a storm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is DHCP snooping?

A

Prevent a rogue DHCP server from handing out false DHCP information

17
Q

What is MAC filtering?

A

Prevent unauthorized devices from connecting to the network.