Network Maps and Topologies Flashcards

1
Q

As an investigator, what is it important that you know when doing a cyber investigation?

A

It is critically important that you know all of the paths between the victim or the suspect at the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What 2 things should you ask from the network administrator when doing a cyber investigation?

A

1) Ask for a network diagram, and
2) Ask how current the diagram is

Want to know any paths to the outside world, where do people get the internet, where does the internet get to them, are there any trusted partners?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

**What do network ports allow us to do?

A

1) allow us to multi-task (run different activities at once and distinguish data packages from other internet activities; without these we would have to finish one activity before info for another packet could come in)
2) ports provide for standardization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
**** What do these assigned ports correspond to:
20
23
25
80
A

20 - FTP data - file transfer protocol
23 - Telnet - old type of VPN
25 - Simple Mail Transfer Protocol (SMTP)
80 - HTTP - in bound web traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are ports?

A

“Virtual Doorways” where info packets pass through

lower #’s are for well known companies and internet activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does “Netstat -ao” do?

A

displays all open ports along with the hostname of the remote computer if available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

**What format are IP Addresses in?

A

4 numbers (ranging between 0-255) separated by periods
In the Decimal format
Each number represents an 8 bit value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can IP addresses be shared?

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the difference between Public IP addresses and Private IP addresses?

A

Public - must have to be able to get on to the internet

Private - Internal address within your organization, and CANNOT be on the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a Dynamic IP Address?

A

when assigned, they are NOT fixed to that node

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Static IP Address?

A

long term address, assigned to a particular resource (printers, routers, camera security systems, servers, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the Private Ranges of IP Addresses?

A
  1. 0.0.0 - 10.255.255.255
  2. 16.0.0 - 172.31.255.255
  3. 168.0.0 - 192.168.255.255
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does a Network Address Translator (NAT) refer to?

A

It refers to a system or server that has one public IP address that goes out to the internet, and numerous private addresses behind it that allow individual computers within a network to access the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Benefits of NAT? (3)

A

1) Security - NAT is protecting private networks from the public
2) It is “Buying Time” for Gen4 IP addresses because you can have thousands of computers that access the internet with 1 Public IP Address
3) Web Cache - will keep a copy of the website that has already been accessed and recall it if asked again instead of going out to the internet and grabbing it again

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How many NIC cards does a NAT need?

A

at least 2:
1 - for the private IP addressed computers
1 - for the public IP addressed server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Address Resolution Protocol (ARP)?

A

this maps IP address to Physical MAC Addresses

Keeps track of all physical MAC addresses on your network

Network Administrator is assigning IP address and entering it manually

17
Q

What is Dynamic Host Configuration Protocol (DHCP)?

A

A server automatically assigns IP addresses to computers on the network when they ask for them

18
Q

What do IP Addresses do?

A

Find an end location - end to end delivery

19
Q

What is the main function of DHCP?

A

Protocol where a user plugs in a device and it gets an IP address