1/203
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
The workstation is
the machine that sits on the desktop
Many threats to information security can start at a
workstation, but much can be done in a few simple steps to provide protection from many of these threats
Servers are the
computers in a network that host applications and data for everyone to share
Mobile devices can create a _____, as a user may access separate e-mail accounts, one personal, without antivirus protection, and the other corporate
major security gap
_____ are well known in the hacker community
Default accounts and passwords
Because of the speed of today’s Ethernet networks, it is possible to manage data storage across the network. This has led to a type of storage known as
Network Attached Storage (NAS)
Network Attached Storage
As a network device, it is
susceptible to attacks
Removable devices can
move data outside of the corporate-controlled environment
Removable devices can bring
unprotected or corrupted data into the corporate environment.
All removable devices
should be scanned by antivirus software upon connection to the corporate environment.
_____ should address the copying of data to removable devices
Corporate policies
Virtualization is an
abstraction of the OS layer
Virtualization
creates the ability to host multiple OSs on a single piece of HW
A major advantage of virtualization is the separation of the software and the hardware. It creates a barrier that can
improve many system functions, including security.
The underlying hardware is referred to as the
host machine, and on it is a host OS.
A _____ is needed to manage virtual machines (VMs).
hypervisor
Virtual machines are typically referred to as the
guest OSs.
Virtualization
_____ and should be applied, independent of the virtualization status.
Patches are still needed
In a virtualization environment, protecting the host OS and hypervisor level is
critical for system stability.
Best practice is to
avoid the installation of any applications on the host-level machine.
Elasticity
refers to the ability of a system to expand/contract as system requirements dictate.
Sandboxing refers to the
quarantine or isolation of a system from its surroundings.
Sandboxing
It is often used to execute
untested or untrusted programs or code, possibly from unverified or untrusted third parties, suppliers, users or websites, without risking harm to the host machine or operating system
_____ can be used as a form of sandboxing with respect to an entire system.
Virtualization
To connect a server or workstation to a network, a device known as a _____ is used. (e.g., Ethernet adaptor card)
network interface card (NIC)
Each NIC port is serialized with a unique code,
48 bits long, referred to as a Media Access Control address (MAC address).
A hub is networking equipment that connects devices that are using the same protocol at the
physical layer of the OSI model.
Hubs
It simply retransmits to
all ports whatever comes through one port → no understanding of layer 2 header
All connections on a hub share a single
collision domain, a small cluster in a network where collisions occur.
Hubs also create a
security weakness due to sniffing and eavesdropping issues.
A _____ operates at the data link layer, filtering traffic based on MAC addresses.
bridge
Bridges can reduce collisions by separating pieces of a network into two
separate collision domains.
A _____ forms the basis for connections in most Ethernet-based LANs. (n ports)
switch
A switch is usually a
Layer 2 device.
Switches
They provide the option to
disable a port so that it cannot be used without authorization.
Switches
They support _____ allowing the administrator to control which systems can send data to each of the ports.
port security
Switches use the _____ of the systems to incorporate traffic filtering and port security feat
MAC address
Switch security concerns
They are intelligent network devices and are therefore
subject to hijacking by hackers.
Switches are commonly administered using the _____ and Telnet protocol.
Simple Network Management Protocol (SNMP)
Switches are shipped with
default passwords.
Switches are subject to electronic attacks, such as _____ → makes eavesdropping and Man-In-The-Middle attack possible
ARP poisoning and MAC flooding
A _____ is a network traffic management device used to connect different network segments.
router
Routers
Operate at the network layer _____ of the OSI model
(Layer 3)
Routers
Use _____ as a method of deciding whether a packet is allowed to enter the network
access control lists (ACLs)
A firewall is a
network device—hardware, software, or a combination thereof.
Firewalls
Its purpose is to enforce a security policy across its connections by
allowing or denying traffic to pass into or out of the network. (between a protected or “Inside” network and less trustworthy “outside” network)
A key to security policies for firewalls is the
principle of least access (privilege).
Packet Filtering Gateway
To perform sophisticated filtering, the _____ must be detailed – complex and error-prone
filtering rule set (ACL)
Application Proxy
- Simulates the proper effects of an application
- Runs a pseudo-application
- Proxy sees inside packets, not only the header data
Next-generation firewalls are characterized by these features:
- Move beyond port/protocol inspection and blocking
- Deep packet inspection (DPI) → Look at the packet payload, not only the header
- Add application-level inspection
- Add intrusion prevention
- Bring intelligence from outside the firewall
A web application firewall is the term given to any software package, appliance, or filter that applies a rule set to _____
HTTP/HTTPS traffic.
A network firewall is a hardware or software package that controls the
flow of packets into and out of a network.
The point of entry from a wireless device to a wired network is performed at a device called a
wireless access point.
Modem is a shortened form of modulator/demodulator, converting
analog signals to digital and vice versa.
A DSL modem is a
device connected to special digital telephone lines using a direct connection.
A cable modem is a
device connected to cable television lines set up in shared arrangements.
The modem equipment provided by the subscription service converts the cable or DSL signal into a
standard Ethernet signal that can then be connected to a NIC on the client device.
The most common security device used in cable/DSL connections is a
router that acts as a hardware firewall.
Cable Modem Security
_____ includes built-in support for security protocols (RSA, DES, AES, X.509)
DOCSIS
A private branch exchange (PBX) is
an extension of the public telephone network into a business.
There are a range of security devices that can be employed at the
network layer to instantiate security functionality in the network layer.
Intrusion detection systems (IDSs) are designed to
detect, log, and respond to unauthorized network or host use, both in real time and after the fact.
Raising an alarm for non-attack:
False positive
No raising an alarm for real attack:
False negative
Load balancers
are designed to distribute the processing load over two or more systems.
Load Balancers
They are used to help
improve resource utilization and throughput but also have the added advantage of increasing the fault tolerance of the overall system.
A proxy server (or simply proxy)
can be used to filter out undesirable traffic and prevent employees from accessing potentially hostile web sites.
Proxy servers can be completely transparent (gateways or tunneling proxies), or a proxy server can
modify the client request before sending it on, or even serve the client’s request without needing to contact the destination server.
Some security vendors combine proxy functions with content-filtering functions to create a product called a _____.
web security gateway
An Internet content filter
protects a corporation from employees’ viewing of inappropriate or illegal content at the workplace and the subsequent complications that occur when such viewing takes place.
Internet Content Filters
They filter
undesirable content, such as pornography and malicious activity such as browser hijacking attempts or XSS attacks
Data loss prevention (DLP) refers to
technology employed to detect and prevent transfers of data across an enterprise. (Prevents insider threat)
Log Management
Purpose
Security breach investigation
SIEM (Security Information and Event Management)
Provides real-time analysis of security alerts generated by network hardware and applications.
Correlation of events across disparate sources
A unified threat management (UTM) appliance refers to
the “all-in-one security appliances”
A UTM simplifies the security activity as a
single task, under a common software package for operations.
UTM
- By consolidating some of these functions, it can simplify management tasks and training requirements.
- can create single point of failure
SIEM
Rather than replacing firewalls, antivirus, or IPS, SIEM works
alongside these devices to collect and correlate information from all of these, as well as the log and event data produced by servers and applications on your network.
SIEM
Intelligently correlate information from disparate systems to
generate a fuller picture of the organization's true security posture.
Coaxial cable has
high bandwidth and shielding capabilities.
Coaxial Cable
- Compared to standard twisted pair lines, coaxial cable (“coax”) is much less prone to outside interference.
- “Vampire tap” security risk exists by drilling hole through the outer part of a coax cable.
Shielded twisted-pair (STP) has
a foil shield around the pairs to provide extra shielding from electromagnetic interference.
Unshielded twisted-pair (UTP) relies on
the twist to eliminate interference.
The standard method for connecting twisted-pair cables is via an 8-pin connector, called an _____.
RJ-45 connector
Fiber
The biggest advantage to fiber is
its bandwidth.
Fiber has one major drawback— _____.
cost
Unguided media have one attribute in common.
- They are unguided and as such can travel to many machines simultaneously.
- Must assume that unauthorized users have access to the signal.
Infrared (IR) cannot penetrate walls but instead
bounces off them.
A sniffer can
record all the network traffic, and this data can be mined for accounts, passwords, and traffic content
Cloud computing is a common term used to
describe computer services provided over a network.
Security is a
particular challenge when data and computation are handled by a remote party, as in cloud computing.
If your organization is highly sensitive to sharing resources, you may wish to consider
the use of a private cloud.
The Use of a Private Cloud
This service will be considerably more expensive, but it should also
carry less exposure and should enable your organization to better define the security, processing, and handling of data that occurs within your cloud.
In most cases, there is little operational difference between public and private cloud architectures, but the
security ramifications can be substantial.
A community cloud system is one where
several organizations with a common interest share a cloud environment for the specific purposes of the shared endeavor.
Sensitive information can be stored in the
private cloud and issue-related information can be stored in the community cloud, all of which information is accessed by an application.
Privileges mean
you have the ability to “do something” on a computer.
Privilege management is
the process of restricting a user’s ability to interact with the computer system.
Authentication is
the process of establishing a user’s identity to enable the granting of permissions.
The term user generally applies to
any person accessing a computer system.