CH16 Securing Networks Flashcards
What is a Privilege Escalation?
occurs when a user is able to gain the rights of another user or administrator
What is a Vertical Privilege Escalation?
goes from a user to an admin account.
What is a Horizontal Privilege Escalation?
privilege escalation goes from one user to another user
What is a Backdoor?
a way of bypassing normal authentication in a system
What are the keys of having a good network security?
An IPS, proper firewall configs, network segmentation, and firmware updates are the keys to having network security
What is EMI ?
EMI = Electromagnetic Interference
a disturbance that can affect electrical circuits, devices, and cables due to radiation or electromagnetic conduction.
EMI can be caused by TVs, microwaves, cordless phones, motors, and other devices.
Shielding the cables (Shielded Twisted Pair - STP) or source can minimize EMI.
What is RFI?
RFI = Radio Frequency Interference
A disturbance that can affect electrical circuits, devices, and cables due to AM/FM transmissions or cell towers.
RFI causes more problems for wireless networks
What is Crosstalk?
occurs when a signal transmitted on one copper wire creates an undesired effect on another wire
Most companies use UTP (Unshielded Twisted Pair cabling) because it’s much cheaper to work with. (vs. Shielded Twisted Pair - STP)
What is Data Emanation?
The electromagnetic field generated by a network cable for device when transmitting.
A Faraday cage can be installed to prevent a room from emanating
To capture them, you need a spectrum analyzer
What is PDS ?
PDS = protected distribution system
PDS helps you protect network medias. It is a secured system of cable management to ensure that wired network remains free from eavesdropping, tapping, data emanations, and other threats
What is SSID?
SSID = Service Set Identifier
Uniquely identifies the network and is the name of the Wireless Access Point (WAP) used by the clients.
For the exam : You should disable the SSID broadcast (hide the name of the Access Point) so that clients have to already know the name of it prior to connecting to it
What is Rogue Access Point?
Unauthorized Wireless Access Point (WAP) or Wireless Router that allows access to the secure network. (Hooking up a wireless access point on a port and sending out signal for the devices to connect).
It can introduce its own DHCP server and cause all sorts of other issues.
To prevent this, you should enable MAC filtering on the network, network access control, and run a good IDS or IPS on your network that can detect or prevent these devices when they initially try to connect
What is an Evil Twin?
a rogue, counterfeit, and unauthorized WAP with the same SSID as your valid one.
To prevent evil twin from being effective by making sure that all of your wireless clients are configured to use a VPN whenever they connect over Wi-Fi even if they’re connecting to your own Wi-Fi
What is Pre-Shared Key?
Same encryption key is used by the access point and the client
What is Open Encryption in terms of wireless network?
No security or protection provided
What is WEP?
WEP = Wired Equivalent Privacy
Original 802.11 wireless security standard that claims to be as secure as a wired network.
WEP’s weakness is its 24-bit IV (Initialization Vector).
NOT secure
What is WPA?
WPA = WiFi Protected Access
Replacement for WEP which uses TKIP, Message Integrity Check (MIC), and RC4 encryption.
WPA was flawed, so it was replaced by WPA2.
What is WPA2?
WiFi Protected Access version 2
802.11i standard to provide better wireless security featuring AES with a 128-bit key, CCMP, and integrity checking.
What is WPS?
WPS = WiFi Protected Setup
Automated encryption setup for wireless networks at a push of a button, but is severely flawed and vulnerable.
Always disable WPS
For wireless Security, what else would you have to do In addition to using WPA2 standard for your encryption?
you should also set up a VPN for your wireless devices.
Encryption and VPNs are always a good idea.
What is WAP?
WAP = Wireless Access Points
Wireless security also relies upon proper WAP placement
What is Omnidirectional antenna WAP?
WAP = Wireless Access Points
access point is going to radiate out its signal equally in every single direction.
What is Bidirectional or unidirectional antenna ?
WAP = Wireless Access Points
controls which direction the signal is actually radiated
What signal does Wireless B, G, and N use?
2.4 GHz signal