4.3 - Security Rules

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/5

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:17 PM on 9/7/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

6 Terms

1
New cards

Access control lists (ACLs)

• Allow or disallow traffic

– Groupings of categories

– Source IP, Destination IP, port number,

time of day, application, etc.

• Restrict access to network devices

– Limit by IP address or other identifier

– Prevent regular user / non-admin access

• Can be implemented in many ways

– Router, firewall, operating system policies, etc.

2
New cards

Firewall rules

• A logical path

– Usually top-to-bottom

• Can be very general or very specific

– Specific rules are usually at the top

• Implicit deny

– Most firewalls include a deny at the bottom

– Even if you didn’t put one

3
New cards

URL filtering

• Allow or restrict based on Uniform Resource Locator

– Also called a Uniform Resource Identifier (URI)

– Allow list / Block list

• Managed by category

– Auction, Hacking, Malware,

– Travel, Recreation, etc.

• Can have limited control

– URLs aren’t the only way to surf

• Often integrated into an NGFW

– Filters traffic based on category or specific URL

4
New cards

Content filtering

• Control traffic based on data within the content

– URL filtering, website category filtering

• Corporate control of outbound and inbound data

– Sensitive materials

• Control of inappropriate content

– Not safe for work

– Parental controls

• Protection against evil

– Anti-virus, anti-malware

5
New cards

Screened subnet

• An additional layer of security between

you and the Internet

– Public access to public resources

– Private data remains inaccessible

6
New cards

Security zones

• Zone-based security technologies

– More flexible (and secure) than IP address ranges

• Each area of the network is associated with a zone

– Trusted, untrusted / Internal, external

– Inside, Internet, Servers, Databases, Screened

• This simplifies security policies

– Trusted to Untrusted

– Untrusted to Screened

– Untrusted to Trusted