Security Flashcards

1
Q

a security architectural frameworks that helps design secure solutions

A

Cisco SAFE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cisco threat intelligence organization

A

Talos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Acquire by Cisco in 2014, a solution that can perform static file analysis (MD5, filenames,), dynamic file analysis, sandbox

A

Cisco Threat Grid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Is a malware analysis and protection solution that goes beyond point-in time detection.

A

Cisco Advance Malware Protection (AMP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Amp components

A

AMP Cloud
AMP connectors
AMP for Endpoints
AMP for Network
AMP for Email
AMP for WEB
AMP for Meraki

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

provide first line of defense against threat on the Internet by blocking request to malicious domain by DNS

A

Cisco Umbrella (OpenDNS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

all-in-one web gateway that includes a wide variety of protections that can block hidden malware from both suspicious and legitimate websites

A

Cisco Web Security Appliance (WSA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A system that passively monitors and analyzes network traffic for potential network intrusion attacks

A

Next-Generation Intrusion Prevention System (NGIPS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

is a collector and aggregator of network telemetry data that performs network security analysis and monitoring to automatically detect threats that manage to infiltrate a network

A

Cisco Stealtwatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Two offering of Stealthwatch

A
  1. Stealthwatch enterprise
  2. Stealthwatch Cloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Is a security policy management platform that provides highly secure network access control (NAC)

A

Cisco Identity Service Engine (ISE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Standard for portbased network access control that provide authentication mechanism for local area network

A

802.1X (dot1x)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

802.1X components

A
  1. Extensible Authentication Protocol (EAP)
  2. EAP Method (EAP Type)
  3. EAP over LAN (EAPoL)
  4. Radius Protocol
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

802.1X roles

A
  1. Supplicant
  2. Authenticator
  3. Authentication Server
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

an access control technique that enables port-base access control using mac-address of endpoint and typically used as a fallback mechanism of 802.1x

A

MAC Authentication Bypass (MAB)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

a next-generation access control developed by Cisco to address growing operational challenge related to maintaining firewall rules and ACLs by using Security Group Tag (SGT)

A

Cisco TrustSec

17
Q

TrustSec Configuration

A
  1. Ingress Classification
  2. Propagation
  3. Egress enforcement
18
Q

IEEE 802.1AE standard base layer 2 hop-by-hop encryption method. traffic is only encrypted only on the wire between to MACsec peer and is unencrypted as it process through the switch

A

MACSec

19
Q

Two MACSec mechanism

A
  1. Security Association Protocol (SAP) - cisco proprietary
  2. MACsec Key Agreement (MKA)
20
Q

encrypted link between and endpoint and a switch

A

Downlink MACSec

21
Q

encrypting a link between switches with 802.1AE

A

Uplink MACSec

22
Q
A