LP - Enterprise Security Capabilities Flashcards
Web filters can filter traffic from OSI
layers 3 to 7
Some Capabilities of web filtering:
- Safe Search
- DNS filtering
- URL filtering
- Content cateorization
- File Filtering
Web filtering can do reputation
filtering
GP stands for
Group Policy
Group Policy (GP) allows administrators to
centrally manage settings on the Windows OS
Is Group Policy (GP) is used in Active Directory?
Yes
GPO stands for
Group Policy Objects
SELinux stands for
Security Enhanced Linux
SELinux in its default enforcement mode will
deny and log any unauthorized attempts (least privilege)
MLS stands for
Multilevel security
SELinux can be confiured to protect a system via
MLS
MLS is very complicated and typically only used by
government
TACACS+ port number
49
Kerberos port number
88
IMAP port number
143, 593
SNMP port number
161/162
FTPS port number
989 and 990
IMAPS port number
993
POP3S pot number
995
RADIUS port number
1812 and 1813
DIAMETER port number
3868
SRTP port number
5004
In DNS filtering all DNS queries are delivered to a
DNS resolver
DNSSEC provides authentication but no
confidentiality
DNSSEC adds the following:
- RRSIG
- DNSKEY
- DS
- NSEC and NSEC3
- CDNSKEY and CDS
RRSIG contains a
cryptographic signature
DNSKEY contains a public
signing key
DS containds the hash of a
DNSKEY record
NEC and NSEC3 is for explicit
denial-of existence of a DNS record
CDNSKEY and CDS is for a child zone requesting update
to DS records in the parent zone
OpenDNS is a cloud-delivered
enterprise security service
SPF stands for
Sender Policy Framework
In SPF the domain owner publishes where the email coming from in the
DNS Zone
DKIM stands for
DomainKeys Identified Mail
How does DKIM work?
It uses digital signatures to verify the email.
DMARC stands for
Domain-based Message Authentication Reporting and Conformance
What is DMARC?
It is an email authentication, policy and reporting protocol.
ICES stands for
Integrated Cloud Email Security
FIM stands for
File Integrity Monitoring (FIM)
EDR stands for
Endpoint detection and response
DAM stands for
Databaase Activity monitoring
IoCs stand for
Indicators of compromise
XDR stands for
extended detection and response
UBA stands for
user behaviour analytics