Implementing a Secure Network Flashcards
What is NAT and PAT
Network Address Translation and Port Address Translation
What are the pros and cons of NAT
Pros:
A router running NAT allows multiple computers to access the internet without purchasing additional public IP addresses.
NAT hides internal computers from the internet
Con:
Not compatible with IPSEC
An advantage of IPSSEC
create VPN tunnels and encrypt with L2TP
Layer 2 switch definition
Uses MAC addresses to deliver traffic. Susceptible to ARP attacks.
Layer 3 switch definition
Uses IP addresses to deliver traffic. Not susceptible to ARP attacks. Allows administrators to create VLANs
what is SCADA
Supervisory Control and Data Acquisition - Used for industrial environments.
In terms of Comptia objectives what refers to providing basic separation.
Segregation
In terms of Comptia objectives what refers to putting traffic on different segments
Segmentation
In terms of Comptia objectives what refers to completely separating systems.
Isolation
A metaphor used for physical isolation
airgap
A typical method for providing logical seperation
VLAN
An effective method of increasing availability and reliability on VOIP data
Use a dedicated VLAN
A device that convert data from the format used to one network to the format used on another network
Media Gateway
A type of server that is used to forward request for services from clients to improve performance or restrict access to inappropriate web sites by filtering content
Proxy Server
What type of proxy uses URL filtering to block employees from visiting inappropriate web sites.
Nontransparent Proxy
Type of server that provides load balancing for a web farm. Allows the web server to be located in the private network behind a second firewall
Reverse Proxy
Device that provides a single solution by combining multiple security controls
UTM - Unified Threat Management
A server that examines all incoming and outgoing email and attempts to reduce risk associated with email.
Mail Gateway
Included in mail gateways to examine outgoing email in an attempt to block confidential and sensitive information from leaving the intranet.
DLP - Data Loss Prevention