1/23
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
FTP port
20/21
FTPS port
989/990
SSH port
22
Telnet port
23
SMTP port
25
SMTPS port
587
TACACS+ Port and Purpose
Port 49, Cisco proprietary protocol used for authentication, authorization, and accounting (AAA) services. Encrypts the whole packet
DNS port
53
DHCP (Dynamic Host Configuration Protocol) Port and Purpose
67/68. Assigns local private IP addresses from one public IPv4 Address
HTTP Port
80
HTTPS port
443
SNMP (Simple Network Management Protocol) Port and Purpose
161/162
LDAP (Lightweight Directory Access Protocol) port
389
LDAPS port
636
RADIUS (Remote Authentication Dial-in User Service)
port and purpose
1812/1813. Provides AAA for network services.
IEEE 802.1X
purpose and roles
Port-Based access control standard. Prevents unauthorized devices from gaining network access without authenticating.
Three roles:
1. Supplicant - the software or device requesting network access.
|
EAPoL (EAP over LAN)
|
2. Authenticator - The network device enforcing access control (e.g. WAP or switch).
|
RADIUS
|
3. Authentication Server - Backend database which validates credentials.
STIX & TAXII
what are they
STIX
Standardized data format (JSON) used to describe cyber threat intelligence.
TRIXX
Transport Protocol for STIX
LDAP and LDAPS
what are they
Protocols used to query and manage objects (like users, devices, groups) in Microsoft Active Directory. LDAP is unencrypted, LDAPS is encrypted using TLS/SSL.
Uses Distinguished Names like:
CN=John West, OU=Sales, DC=domain
Look for keywords like “Query Active Directory”, “Look up user details”
RADIUS
what is it? UDP or TCP? What gets encrypted?
Centralized AAA (Authentication, Authorization and Accounting) protocol. Used to control network access for remote users, VPN connections, and enterprise Wi-Fi (802.1X).
Authentication and Authorization in combined packets on port 1812.
Accounting (logging session times, login attempts etc.) on port 1813.
Encrypts only the user password in the packet payload (header and username unencrypted).
Uses UDP.
TACACS+
what is it? UDP or TCP? What gets encrypted?
Cisco AAA protocol for network devices (CLI access to firewalls, switches, routers, admin consoles via SSH).
Separates AAA into separate packets.
Encrypts the entire packet payload.
Uses TCP.
EAP-TLS vs EAP-TTLS.
Client Certificate? Password Risk? Best For? PKI Requirement?
EAP-TLS
High-overhead (full PKI) and highly secure.
Client Certificate: Required.
Passwordless.
Best for Corporate-owned, fully managed devices.
EAP-TTLS
Lower overhead (only need a certificate on the server).
Client Certificate: Not required.
Password sent through TLS tunnel.
Best for BYOD, guest networks.
TT = Tunneled transport. Creates a TLS tunnel with server cert, then transfer username and password with legacy protocols.
SAML (Security Assertions Markup Language)
What is it? What is it used for? Three key components.
SAML is the standard for XML-based web Single-Sign-On (SSO) in enterprise environments.
Key Components:
Principal (User): Requests access to a service.
Identity Provider (IdP): Authenticates the user (e.g. Okta)
Service Provider (SP): The SaaS application granting access (e.g. Zoom)
Exam key: Look for “XML-based assertions”, “Identity Provider”, “Service Provider”, “Enterprise SSO/SaaS”.
OAuth 2.0, OpenID Connect
Which is Authorization vs Authentication?
When to use?
OAuth 2.0: Authorization - what resources can this app access?
OAuth 2.0 uses an access token to allow an app to access resources.
OpenID Connect: Authentication - who is this user?
OpenID Connect is built on OAuth, uses an JWT ID token to allow a user to “Log in with Google”
WPA-2 vs WPA-3
What authentication method? Forward Secrecy?
WPA-2
Auth method: Pre-shared key
Forward Secrecy: No
WPA-3
Auth method SAE: (Simultaneous Authentication of Equals). Eliminates offline/dictionary attacks on captured files.
Forward Secrecy: Yes (via dragonfly handshake)