Chapter 12 Security+ SYS-701

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/48

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:26 AM on 10/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

49 Terms

1
New cards

What do layers 1-3 of the OSI model do?

For media (physical, data link, network)

2
New cards

What do layers 4-7 of the OSI model do?

Transport through applications

3
New cards

What is a DMZ?

A network that is in between the internet and the LAN. Usually surrounded by 2 firewalls. Purpose is to protect lan from external traffic

<p>A network that is in between the internet and the LAN. Usually surrounded by 2 firewalls. Purpose is to protect lan from external traffic</p>
4
New cards

What does fail-closed mean?

If a security device fails, then don’t allow traffic through

5
New cards

What is a network tap?

Devices used to monitor traffic

6
New cards

What does active & passive network tap mean?

Active —> powered

Passive —> no power

7
New cards

What is an inline network tap?

Has all traffic flowing through it

8
New cards

What are reputation services?

Services that monitor data to block malicious IP’s, domains, and hosts

9
New cards

What is SDN?

Software defined network

10
New cards

What is SD Wan?

Using multiple wan networks for reliability (like fiber + lte)

11
New cards

What is SASE?

Secure Access Service Edge - Cloud-based security + SD-WAN + VPN/Zero Trust concepts.

12
New cards

What is the Extranet

A private network that gives access to authorized access users to some resources

13
New cards

What does East/West traffic mean?

Traffic between systems inside a network

14
New cards

What does adaptive identity mean in the zero trust model?

Uses multiple data points like user/device/location to establish and identity

15
New cards

What is the different between agent and agentless network access control (NAC)?

Agent NAC requires software running on the device and does better job, agentless is more network based

16
New cards

What is bpdu guard

BPDU is message used in STP, and BPDU guard shuts down switch port if it receives that message to prevent network loops

17
New cards

What is a site-site VPN?

Network to Network VPN

18
New cards

What is full tunnel VPN?

When all network traffic is redirected through the vpn

19
New cards

What is a split-tunnel VPN?

Only organization traffic is done through VPN

20
New cards

What layer is IPSec?

Layer 3

21
New cards

Describe layout of a forward proxy?

Client —> proxy —> internet


Designed to proect data going out

22
New cards

Describe layout of a reverse proxy?

Client —> proxy —> webserver


Designed to protect traffic coming in, determines who can access recourses

23
New cards

What is a stateless firewall?

Examines individual packets and makes descions based on info in the packets (like source and destination IP, etc.)

24
New cards

What is a stateful firewall?

Tracks multiple packets and looks at the entire conversation before making a decision

25
New cards

What is a UTM device?

Unified threat management device - has firewall, ips/ids, url and email filtering, etc.

26
New cards

What is a honeynet?

A network of fake honeypots

27
New cards

What is a honeytoken?

A fake/trackable data, not to be confused with a honeyfile

28
New cards

What is DKIM?

digitally signs email.

29
New cards

What is SPF?

identifies authorized sending servers.

30
New cards

What is DMARC?

uses SPF + DKIM to decide what to do with unauthenticated email.

31
New cards

What are ephemeral keys?

temporary encryption keys created for a single session or short period.

32
New cards

What is an SNMP trap?

Like a monitoring alert

33
New cards

What is FIM?

File integrity monitoring

34
New cards

Secure ports

knowt flashcard image
35
New cards

What is DNSSEC used for?

Digitally signs DNS records to verify authenticity and integrity. Does not encrypt DNS traffic.

36
New cards

What is required to make SNMPv3 secure?

authPriv

37
New cards

What is ESP?

Encapsulating Security Payload

38
New cards

What is transport mode in IPSec?

Protects the packet payload

39
New cards

What is tunnel mode in ip sec?

Protects the entire original IP packet by encapsulating it; commonly used for site-to-site VPNs.

40
New cards

How is NTP authentication secured?

Using NTS

41
New cards

What is SSL stripping?

Downgrades HTTPS connections to HTTP to expose traffic.

42
New cards

How can SSL stripping be combated?

By using HSPSTS - forces browsers to use HTTPS.

43
New cards

What is a SYN flood?

Sends TCP SYN requests without completing the handshake, exhausting resources.

44
New cards

What is amplification attack?

Small request generates a much larger response.

45
New cards

What is a reflection attack?

Spoofed victim IP causes third-party servers to send traffic to the victim.

46
New cards

What is a smurf attack?

Spoofed ICMP broadcast traffic overwhelms a victim.

47
New cards

What is xmas attack?

Uses unusual TCP flag combinations to probe or target systems.

48
New cards

What are on-path attacks?

take advantage of malicious browser plug-ins or proxies to modify traffic at the browser level.

49
New cards

What are PEP’s?

Policy enforcement points - Sits between user and resource rwards requests and enforces the access decision.