Why use defense in depth for network security?
Network security uses multiple layers of protection so that if one control fails, other controls can help detect an intrusion or limit what it can reach.
Study 5 Network Security with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
Why use defense in depth for network security?
Network security uses multiple layers of protection so that if one control fails, other controls can help detect an intrusion or limit what it can reach.
What does zero trust evaluate?
Zero trust evaluates whether access to a particular resource should be allowed instead of assuming that everything inside a network is trustworthy.
What security do IP, TCP, and UDP provide by themselves?
IP provides addressing and routing, while TCP and UDP carry application traffic. These protocols do not by themselves encrypt or authenticate communications.
What protections can HTTPS provide through TLS?
HTTPS is HTTP carried over TLS. Correctly configured TLS can provide confidentiality, integrity, and server authentication when the client validates the server’s certificate.
What is SSH commonly used for?
SSH provides an encrypted, authenticated channel commonly used for remote administration and secure file transfer. Administrators should verify host keys and manage authentication carefully.
At what layer does IPsec protect traffic?
IPsec protects IP traffic at the network layer. It can secure traffic between hosts, between security gateways, or between a host and a gateway, and is commonly used in VPNs.
What do DoT and DoH protect, and what do they not guarantee?
DNS over TLS (DoT) and DNS over HTTPS (DoH) encrypt the client-to-resolver exchange, but do not hide all network metadata or guarantee that a requested destination is safe.
How can SNMPv3 help secure network management?
SNMPv3 supports authentication and encryption options for network management. When SNMP is needed, use it with authentication and encryption.
What makes a firewall traffic policy restrictive and specific?
A firewall policy should allow only traffic required for a defined purpose and deny other traffic. Rules should specify source, destination, service, and direction.
What is network segmentation?
Network segmentation divides a network into zones with controlled access between them, so devices and services do not all share unrestricted connectivity.
Why is a VLAN alone not a complete security boundary?
A VLAN alone is not a complete security boundary if routing between VLANs is unrestricted; access between segments still needs policy enforcement.
What is the security purpose of a DMZ?
A DMZ is a zone for services that must be reachable from less-trusted networks. It limits direct exposure of internal systems by restricting connections from the DMZ to back-end services.