OSI Model and Security Threats Flashcards

1
Q

List Threats + Solutions to Layer 1 Security.

A

Threats: Wiretapping. Physical security of servers. Solutions: Security locks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List Threats + Solutions to Layer 2 Security.

A

Threats: VLAN Hopping Attack. Configuration of Ethernet Switches and VLAN can make the attack easier.

Configurations: Access - assigned to single VLAN. Trunk - interconnect with multi-switches w/ multi VLANS.

Solution: Configure in Access mode.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List Threats + Solutions to Layer 3 Security.

A

Threats: DoS/DDoS. Ping sweep. Spoofing.

Solutions: Pocket filter firewall, IPS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

List Threats + Solutions to Layer 4 Security.

A

Threats: Port scanner - scans victims comp for open ports.

Solution: Packet-filter firewall. Port redirection - redirects web requests to less known port. Not very effective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

List Threats + Solutions to Layer 5 Security.

A

Threats: Attack on Remote Procedure Protocol (RPC). RPC used to execute procedures on other comps (like a printing job).

Solution: OS + App patches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

List Threats + Solutions to Layer 6 Security.

A

Threat: Man in the middle on TLS/SSL.

Solution: App-layer proxy or IPS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

List Threats + Solutions to Layer 7 Security.

A

Threats: Attack on webservers or APIs. Another can access API without authorization.

Solution: MFA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly