Security Theory Flashcards
Access Control, CoPP, AAA
What is the name of the Cisco Security Architectural Framework?
Cisco SAFE
What are the PINs (Places In Network) where you would see Cisco SAFE deployed?
- Branch
- Campus
- Data Center
- Edge
- Cloud
- WAN
What are the operational domains that Cisco SAFE defines?
- Management
- Security Intelligence
- Compliance
- Segmentation
- Threat Defense
- Secure Services
What three intelligence teams make up Cisco Talos?
- Ironport Security Applications
- Sourcefire Vulnerability Research Team (VRT)
- Cisco Threat Research, Analysis, and Communications Team (TRAC)
What is Cisco Threat Grid?
A complex virtual sandbox that that observes and analyzes static files for the behavior of malware.
What is Cisco AMP?
Advanced Malware Protection - comprehensive malware protection across the full attack continuum: Before, During, and After a breach occurs.
What are the key components of the Cisco AMP architecture?
- AMP Cloud
- Threat intelligence from Talos and Threat Grid
- AMP Connectors (Endpoints, Networks, Email, Web, Meraki)
What is Cisco Umbrella?
A Cloud-based secure DNS solution that blocks malicious Internet destinations.
What is Cisco WSA?
Web Security Appliance - URL filtering, malware-block, Data Loss Prevention, Anti-Virus scanning
What is Cisco ESA?
Email Security Appliance - includes global threat intelligence, spam protection, reputation filtering, forged email protection, domain protection, DLP, Phishing protection
What is NGIPS?
Next Generation Intrusion Protection System
What is the name of Cisco’s NGIPS?
Firepower
What are the key characteristics of any NGIPS?
- Real time contextual awareness
- Advanced threat protection
- Intelligent security automation
- Performance and scalability
- Application Visibility and Control (AVC)
- URL filtering
What are the key characteristics of a Next Generation Firewall (NGFW)?
- Stateful packet inspection
- Integrated IPS
- Application level packet inspection
- leverages external security intelligence
What is Cisco Stealthwatch?
Collector of network telemetry data that can perform security analysis on the network data.
What is Cisco ISE?
Identity Services Engine - a security policy management platform that performs Network Access Control (NAC) and 802.1x functions and more.
What are some of the key benefits to Cisco ISE?
- Network Access Control
- DNA Center integration
- Device Access Control, onboarding, and profiling
- Cisco TrustSec
- Guest Lifecycle Management
- Internal Certificate Authority
- Endpoint posture service
- Cisco Platform Exchange Grid (pxGrid)
What is pxGrid and what role does ISE play in pxGrid?
Platform Exchange Grid - an IETF framework that uses a single API to exchange security information to mitigate and remediate security threats across the network. Cisco ISE acts as the pxGrid Controller (aka server).
List the five most prolific types of Network Access Control (NAC)
- 802.1X
- Mac Address Bypass (MAB)
- WebAuth
- TrustSec
- MacSec
What are the four main components of 802.1x?
- Extensible Authentication Protocol (EAP)
- EAP Method aka EAP Type
- EAP over LAN (Layer 2)
- RADIUS protocol
What is 802.1X?
An IEEE Standard for authenticating devices that are trying to connect to a network. AAA, Radius, WLCs, and/or Cisco ISE are core components in an 802.1X deployment.
What are the device roles in an 802.1x deployment?
- Supplicant
- Authenticator
- Authentication Server
What is the role of a Supplicant in an 802.1x deployment?
The software on the endpoint that is attempting to authenticate to the network. This could be the Operating system or a Cisco AnyConnect client.