Chapter 7 - Administering A Secure Network Flashcards
Simple network management protocol (SNMP)
A TCP/IP protocol that exchanges management information between networked devices. It allows network administrators to remotely monitor, manage, and configure devices in the network.
Domain name system security extensions (DNSSEC)
An extension to DNS that adds additional resource records and message header information, used to verify that DNS data has not been altered in transmission.
File transfer protocol (FTP)
An unsecure TCP/IP protocol that is commonly used for transferring files.
FTP Secure (FTPS)
A TCP/IP protocol that uses Secure Sockets Layer or Transport Layer Security to encrypt commands sent over the control port (port 21) in an FTP session.
Secure FTP (SFTP)
A secure TCP/IP protocol that is used for transporting files by encrypting and compressing all data and commands.
SSL/TLS accelerator
A separate hardware card that inserts into a web server that contains one or more co-processors to handle SSL/TLS processing.
Port mirroring
A facility that allows the administrator to configure a switch to copy traffic that occurs on some or all ports to a designated monitoring port on the switch.
Network tap (test access point)
A separate device that can be installed on the network for monitoring traffic.
Aggregation switch
A device used to combine multiple network connections with not a single link.
Correlation engine
A device that aggregates and correlates content from different sources to uncover an attack.
DDoS mitigator
A hardware device that identifies and blocks real-time distributed denial of service (DDoS) attacks.
Log
A record of events that occur.
Data execution prevention (DEP)
A Microsoft Windows feature that prevents attackers from using buffer overflow to execute malware.
File integrity check (FIC)
A service that can monitor any changes made to computer files.
Application whitelisting
An inventory of applications and associated components (libraries, configuration files, etc.) that have been pre-approved and authorized to be active and present in the device.