Final Exam Prep - Lecture Items Flashcards

1
Q

defense-in-depth

A

the most important firewall principle is to

multiple layers of defense mechanisms:

  • The first line is a prevention mechanism
  • second line is detection and response mechanisms
  • third is attack resilient technologies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DMZ

A

his public facing service, that while it is part of the enterprise network, it is separated from
the trusted network. For example, while customers can interact with
the web service in the DMZ to log
in and submit transaction requests, they cannot directly access the servers in the trusted network that
are authorizing and processing the transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Typically the systems in the ________ require or foster external connectivity such as a corporate Web site, an e-mail server, or a DNS server.

A

DMZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Firewalls can stop Hackers breaking into your system

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

T/F Firewalls can stop viruses and worms that spread through email

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

viruses and worms that spread through THE INTERNET

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Examples of IPSec security measures

A
authentication of source IP addresses, 
confidentiality and integrity protection of packet data. 
And authenticity of packet data, 
in particular preventing replay of 
packets.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IP Spoofing is used for

A

Unidirectional Communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

2 operation modes of IPSec

A

Transport

Tunnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IPSec can assure that a router advertisement comes from an authorized router

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

IPSec can assure that a routing update is not forged

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IPSec can assure that a redirect message comes from the router to which the initial packet was sent

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

3 parts of IPSec architecture

A

ESP - Encapsulating Security Payload
Authentication Header - AH
Internet Key Exchange - IKE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ESP stands for

A

Encapsulated Security Payload

How well did you know this?
1
Not at all
2
3
4
5
Perfectly