1/17
Vocabulary flashcards covering core concepts of Network Security Design including Firewalls, VPNs, DMZs, Defense in Depth, and Zero Trust.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Firewall
A system at a network's entry/exit point that allows or denies communication according to rules set in advance.
VPN
A technology that creates an encrypted virtual private line (tunnel) over the Internet for safe remote connection.
DMZ
An area where servers exposed to the external network—such as web and mail servers—are placed separately from the internal network.
Defense in Depth
The concept of layering multiple security measures so that, even if one measure is breached, the next can still protect the system.
Zero Trust
A security concept in which no communication including communication from inside the organization is trusted automatically; every access is verified.
Layer 1: Network entry
The defense layer that blocks unauthorized communication at the network entry/exit boundary using a firewall.
Layer 2: Communication path
The defense layer that secures transit by encrypting communication using a VPN.
Layer 3: Server placement
The defense layer that isolates public-facing servers from the internal network using a DMZ.
Layer 4: Endpoints
The defense layer that protects individual user devices by installing antivirus software and keeping the operating system updated.
Identity (Zero Trust)
The first verification step in Zero Trust security that answers 'Who is requesting access?'.
Permission (Zero Trust)
The second verification step in Zero Trust security that determines 'Are they allowed to use this resource?'.
Every Time Verification
The principle in Zero Trust requiring identity verification and access-permission checks for every request, even for access originating from inside the organization.
Traditional Perimeter Security
A conventional security model built on the premise that inside the organization's network is safe and trusted, while outside is untrusted and dangerous.
Public-facing servers
Servers (such as web and mail servers) that must accept outside traffic, making them more exposed to attack than internal servers.
Eavesdropping
A network security risk on public Wi-Fi that is reduced by using VPN encryption.

DMZ Network Configuration
A architecture separating external traffic from internal confidential data by placing web/mail servers in a demilitarized zone flanked by two firewalls.

Traditional vs. Zero Trust Architecture
A comparison showing that traditional security relies on a single firewall boundary to trust internal users, whereas Zero Trust verifies every user, device, app, and data access regardless of location.
Dr. Mohammed Abdalla Mahmoud Youssif
AI Professor and Technology Consultant who taught the Network Security Design lecture.