Chapter 5 Key Terms Flashcards
Security Zone
Portions of the network or system that have specific security concerns or requirements.
Wireless network
A network that does not require a physical connection.
Guest network
A network that grants internet access only to guest users. A guest network has a firewall to regulate guest user access.
Honeynet
A special zone or network created to trap potential attacks.
Ad hoc
A decentralized network that allows connections without a traditional base station or router. It allows users to connect two or more devices directly to each other for a specific purpose.
Intranet Zone
A private network that employs internet information services for internal use only.
Internet
A public network that includes all publicly available web servers, FTP servers, and other services.
Extranet
A privately-controlled network distinct from but located between the internet and a private LAN.
Demilitarized zone
A network that contains publicly accessible resources and is located between the private network and an untrusted network, such as the internet. It is protected by a firewall.
Proxy server
A type of firewall that stands as an intermediary between clients requesting resources from other servers.
Internet content filter
Software used to monitor and restrict content delivered across the web to an end user.
Network access control
Software that controls access to the network by not allowing computers to access network resources unless they meet certain predefined security requirements.
All-in-one security appliance
An appliance that combines many security functions into a single device.
Application-aware devices
A device that has the ability to analyze and manage network traffic based on the application-layer protocol.
Demilitarized zone (DMZ)
A buffer network (or subnet) that is located between a private network and an untrusted network, such as the internet.
Bastion or Sacrificial Host
Any host that is exposed to attack and has been hardened or fortified against attack.
Screening router
The router that is most external to the network and closest to the internet.
Duel-homed gateway
A firewall device that typically has three network interfaces. One interface connects to the internet, one interface connects to the public subnet, and one interface connects to the private network.
Screened-host gateway
A device residing within the DMZ that requires users to authenticate in order to access resources within the DMZ or the intranet.
Screened subnet
A subnet protected by two firewalls; an external firewall is connected to the internet and an internal firewall is connected to a private network.
Network Address Translation
A method used by routers to translate multiple private IP addresses into a single registered IP address.
Internal network
The private network where devices use private IP addresses to communicate with each other.
Internal address
The private IP address that is translated to an external IP address by NAT.
External network
The public network that a NAT device connects to with a single public IP address.
External address
The public IP address that NAT uses to communicate with the external network.
Port Address Translation (PAT)
An extension of NAT that associates a port number with a request from a private host.
Virtual Private Network
A remote access connection that uses encryption to securely send data over an untrusted network.