Unit 2 Lesson 2-2: Network Security Design

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering core concepts of Network Security Design including Firewalls, VPNs, DMZs, Defense in Depth, and Zero Trust.

Last updated 8:05 PM on 10/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards

Firewall

A system at a network's entry/exit point that allows or denies communication according to rules set in advance.

2
New cards

VPN

A technology that creates an encrypted virtual private line (tunnel) over the Internet for safe remote connection.

3
New cards

DMZ

An area where servers exposed to the external network—such as web and mail servers—are placed separately from the internal network.

4
New cards

Defense in Depth

The concept of layering multiple security measures so that, even if one measure is breached, the next can still protect the system.

5
New cards

Zero Trust

A security concept in which no communication including communication from inside the organization is trusted automatically; every access is verified.

6
New cards

Layer 1: Network entry

The defense layer that blocks unauthorized communication at the network entry/exit boundary using a firewall.

7
New cards

Layer 2: Communication path

The defense layer that secures transit by encrypting communication using a VPN.

8
New cards

Layer 3: Server placement

The defense layer that isolates public-facing servers from the internal network using a DMZ.

9
New cards

Layer 4: Endpoints

The defense layer that protects individual user devices by installing antivirus software and keeping the operating system updated.

10
New cards

Identity (Zero Trust)

The first verification step in Zero Trust security that answers 'Who is requesting access?'.

11
New cards

Permission (Zero Trust)

The second verification step in Zero Trust security that determines 'Are they allowed to use this resource?'.

12
New cards

Every Time Verification

The principle in Zero Trust requiring identity verification and access-permission checks for every request, even for access originating from inside the organization.

13
New cards

Traditional Perimeter Security

A conventional security model built on the premise that inside the organization's network is safe and trusted, while outside is untrusted and dangerous.

14
New cards

Public-facing servers

Servers (such as web and mail servers) that must accept outside traffic, making them more exposed to attack than internal servers.

15
New cards

Eavesdropping

A network security risk on public Wi-Fi that is reduced by using VPN encryption.

16
New cards
<p>DMZ Network Configuration</p>

DMZ Network Configuration

A architecture separating external traffic from internal confidential data by placing web/mail servers in a demilitarized zone flanked by two firewalls.

17
New cards
<p>Traditional vs. Zero Trust Architecture</p>

Traditional vs. Zero Trust Architecture

A comparison showing that traditional security relies on a single firewall boundary to trust internal users, whereas Zero Trust verifies every user, device, app, and data access regardless of location.

18
New cards

Dr. Mohammed Abdalla Mahmoud Youssif

AI Professor and Technology Consultant who taught the Network Security Design lecture.