(2) Network Architecture Flashcards

1
Q

What is included in the term On-Premises network architecture?

A

On-Premises network architecture includes routers, switches, security devices, cabling, and other network components that comprise a regular network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Since Cloud services don’t normally allow network admins to directly access the physical devices that provide the service, what do network admins have to do instead to secure these systems?

A

With Cloud systems, contractual obligations are important, especially when it comes to Software as a Service (SaaS) and Platform as a Service (PaaS) vendors.

Identity and Access Management is also super important.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Type of security controls do Infrastructure as a Service (IaaS) vendors provide?

A

IaaS vendors like AWS and Azure provide more security controls because there is more access to Infrastructure.

In that way, the same type of security controls that one would implement with on premises systems would apply.

Cloud providers also often provide their own additional security controls too.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Virtual Private Cloud (VPC)?

A

VPC is delivered by cloud service providers that builds an on demand environment that is semi isolated.

Normally it is placed on a private subnet and has extra security to make sure that activities stay private

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does it mean when you “air gap” a system?

A

“air gap” when it comes to a system means that there isn’t a direct connection between one network and another

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does network segmentation help network exposure?

A

Network segmentation limits network exposure by reducing the attack surface of the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does segmentation help compliance efforts?

A

Segmentation helps compliance efforts because one can place compliant systems on a more easily maintained environment separate from the rest of the org.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does segmentation help availability?

A

Segmentation helps availability by reducing the impact of an attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How is network segmentation normally maintained?

A

Normally network segmentation happens by using a firewall with a meticulously configured ruleset normally used between network segments.

Different levels of trust are configured too.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When it comes to network segmentation, what specific feature should routers and switches support?

A

Routers and switches should support VLAN (virtual local area network) tagging for more sophistication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When it comes to network segmentation, what is a jump box?

A

When it comes to network segmentation, a jump box (also called a jump server) is a system that resides in a segmented environment and is used to access and manage devices in a segment where the jump box is located.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many security zones do jump boxes cover?

A

Jump boxes cover two different security zones and should also be secured, managed, and monitored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Software Defined Networking (SDN)?

A

SDN lets you program networks. Central control of networks is possible and you can manage the network resources with more intelligence than a regular physical network.

APIs are used to provide these services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is important to include in Software Defined Networking (SDN) setups?

A

API security and secure code development practices are very important to include in SDN setups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are Software Defined Network Wide Area Networks (SDN-WANs)?

A

SDN-WANs are a service model where provides use SDN technology to build networks.

This setup allows orgs to have a variety of technologies integrated in one solution. It does offer encryption too.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are some risks of SDN-WANs?

A

With SDN-WANs, there are risks such as vulnerabilities of the SDN platform, risks involving various vendors who may be involved in the network, and risks related to integrity as traffic flows through a lot of different paths.

17
Q

What is the concept of Zero Trust?

A

Zero Trust is all about verifying everything before it happens.

This concept involves every layer of the security system as being important instead of just the perimeter, essentially creating a multi layered security system.

18
Q

What is required to implement zero trust in a tech environment?

A

To implement Zero Trust, it requires a mix of technologies, processes, policies and more to keep the system running properly.

19
Q

What is Secure Access Service Edge (SASE)?

A

SASE is a rather complex mix that uses Software Defined Wide Area Networking (SD-WAN) security features, such as Cloud Access Security Brokers (CASB), zero trust, firewall technologies, antimalware programs, and more to provide network security.

20
Q

What goal is Secure Access Service Edge (SASE) aimed at?

A

SASE is aimed at creating security at both the endpoint and network layer, especially if the org is decentralized and that datacenter only models of security are not as useful.

21
Q
A