Section 11 Part two

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/36

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:40 PM on 6/19/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

37 Terms

1
New cards

Load Balancer Active/Active Setup

both load balancers are active and share the traffic simultaneously. Traffic is distributed between the two load balancers based on pre-defined rules.

2
New cards

Load Balancer Active/Active Setup Usage

Suited for high-traffic environments where load distribution is essential for optimal performance.

3
New cards

Load Balancer Active/Active Setup Advantage

Enhances capacity and reliability of the service. Reduces risk of downtime.

4
New cards

Load Balancer

a device or software that evenly distributes network or application traffic across multiple servers to prevent any single server from becoming overburned, which improves overall performance and reliability.

5
New cards

Hardware Load Balancers

physical devices specifically designed for load balancing. Typically more powerful.

6
New cards

Software Load Balancers

can run on standard hardware or in cloud environments. They offer more flexibility and are often more cost-effective.

7
New cards

Load Balancer Active/Passive Setup

One load balancer is active and handles all the traffic while the other remains passive (idle) as a standby. Improves reliability not performance.

8
New cards

Load Balancer Active/Passive Usage

Ideal for scenarios where uninterrupted service is critical but where simultaneous operation of two load balancers is not necessary.

9
New cards

Load Balancer Active/Passive Advantage

Provides a reliable backup, ensuring continuity of service

10
New cards

802.1x

is an IEEE standard for post-based Network Access Control (PNAC). It is used to authenticate devices that are attempting to connect to a LAN or WLAN.

11
New cards

EAP (Extensible Authentication Protocol)

is a framework frequently used in network access control for various authentication methods.

12
New cards

EAP

is designed to support multiple authentication mechanisms, including passwords, tokens, certificates, and public key encryption. Part of IEEE 802.1X standard for network access control.

13
New cards

Packet filtering Firewalls

the most basic type, which inspects packets or permits or denies them based on source and destination IP addresses, ports, protocols. (No longer used)

14
New cards

Stateful Inspection Firewalls

more advanced than packet filtering, these firewalls track the state of active connections and make decisions based on the context of the traffic. (All firewalls based on this)

15
New cards

Web Application Firewall (WAF)

are specifically designed to protect web apps by filtering and monitoring HTTP traffic between web app and the internet. They are effective in preventing web app attacks such as XSS, SQL injection, and session hijacking.

16
New cards

WAFs operate at the application layer and apply a set of rules to an HTTP conversation.

True

17
New cards

Unified Threat Management (UTM)

provide a comprehensive solution that combines multiple security features and services in a single device. These include features like anti-virus, anti-spyware, ids & ips

18
New cards

Advantage of UTM

is the simplicity and ease of management as it consolidates multiple security features, ideal for medium and small businesses.

19
New cards

NGFW

more advanced version of a firewall, integrating things like deep packet inspection, intrusion prevention, and application awareness

20
New cards

Deep Packet Inspection (DPI)

NGFW go beyond port/protocol inspection and blocking to inspect the data with the packets themselves.

21
New cards

Difference between UTM and NGFW is

NGFW’s are more customizable

22
New cards

WAF is considered in Layer 7 in OSI

True

23
New cards

What layer is firewall under

Layer 4

24
New cards

What layer is proxy under

Layer 7

25
New cards

VPN

is a technology that creates an encrypted connection over a less secure network. It establishes secure communication paths through the internet between two distant networks.

26
New cards

Tunneling

The encapsulation of a protocol- deliverable message within a second protocol.

27
New cards

TLS (Transport Layer Security)

operates at level 4 of OSI model. Type of tunnel that uses TLS/SSL encryption of data; uses port 443.

28
New cards

L2TP

is a standard protocol for tunneling L2 traffic over an IP network. Hybrid of Layer 2 forwarding. Creates a point to point tunnel between communication endpoints. Uses IPsec as the security mechanism.

29
New cards

IPSec

a standalone VPN protocol, a security mechanism for L2TP, provides secure authentication and encryption.

30
New cards

IPSec Components

Authentication Header
Encapsulating Security Payload

31
New cards

Authentication Header

provides authentication, integrity, and non-repudiation, has replay protection using sequence number.

32
New cards

Encapsulating Security Payload

provides encryption to protect confidentiality of transmitted data.

33
New cards

Two modes for IPSec

Tunnel Mode
Transport Mode

34
New cards

Tunnel Mode

Payload and headers are protected; final destination is hidden. must decrypt packet at each hop.

35
New cards


Transport Mode

Payload protected; final destination is visible; can be routed w/o decryption.

36
New cards

SD-WAN

overlays your network and its going to allow for efficient network traffic that allows applications to be used correctly and efficiently. making data routing more efficient.

37
New cards

SASE

is a cloud native networking architecture that combines network security functions with WAN capabilities to support the dynamic secure access needs of organizations. It merges SD-Wan capabilities with comprehensive security services.