Network Security Fundamentals Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security Fundamentals flashcards as text
Which protocol provides secure, encrypted remote administration of network devices and replaces Telnet?
Answer: SSH
SSH (Secure Shell) encrypts all traffic between client and server, replacing the plaintext Telnet protocol for secure remote administration.
A network administrator wants to prevent unauthorized devices from connecting to the corporate LAN. Which technology should be implemented?
Answer: 802.1X port-based Network Access Control
802.1X enforces authentication before granting network access, ensuring only authorized devices can connect to LAN ports.
In the context of the CAP framework, what does 'defense-in-depth' mean for network security?
Answer: Layering multiple security controls so no single failure exposes assets
Defense-in-depth means implementing multiple overlapping security layers so that a failure in one control does not leave systems unprotected.
Which type of attack involves an attacker intercepting and potentially altering communications between two parties without their knowledge?
Answer: Man-in-the-Middle (MitM)
A Man-in-the-Middle attack occurs when an adversary secretly intercepts and can modify communications between two parties who believe they are communicating directly.
What is the primary function of a demilitarized zone (DMZ) in network security architecture?
Answer: To host public-facing services while protecting the internal network
A DMZ is a network segment that hosts public-facing services (e.g., web servers) while keeping them isolated from the trusted internal network.
Which network security device inspects traffic at the application layer and can make decisions based on the content of packets?
Answer: Next-Generation Firewall (NGFW)
Next-Generation Firewalls operate at layer 7, performing deep packet inspection and making policy decisions based on application identity and content.
When implementing network segmentation, what is the primary security benefit?
Answer: Limits the blast radius of a security breach by containing lateral movement
Network segmentation contains breaches within a segment, preventing attackers from freely moving laterally across the entire network.