Final Exam Prep - Lecture Items Flashcards
defense-in-depth
the most important firewall principle is to
multiple layers of defense mechanisms:
- The first line is a prevention mechanism
- second line is detection and response mechanisms
- third is attack resilient technologies
DMZ
his public facing service, that while it is part of the enterprise network, it is separated from
the trusted network. For example, while customers can interact with
the web service in the DMZ to log
in and submit transaction requests, they cannot directly access the servers in the trusted network that
are authorizing and processing the transactions.
Typically the systems in the ________ require or foster external connectivity such as a corporate Web site, an e-mail server, or a DNS server.
DMZ
Firewalls can stop Hackers breaking into your system
True
T/F Firewalls can stop viruses and worms that spread through email
False
viruses and worms that spread through THE INTERNET
True
Examples of IPSec security measures
authentication of source IP addresses, confidentiality and integrity protection of packet data. And authenticity of packet data, in particular preventing replay of packets.
IP Spoofing is used for
Unidirectional Communication
2 operation modes of IPSec
Transport
Tunnel
IPSec can assure that a router advertisement comes from an authorized router
True
IPSec can assure that a routing update is not forged
True
IPSec can assure that a redirect message comes from the router to which the initial packet was sent
True
3 parts of IPSec architecture
ESP - Encapsulating Security Payload
Authentication Header - AH
Internet Key Exchange - IKE
ESP stands for
Encapsulated Security Payload