Shared Flashcard Set

Details

CompTIA Sec+ 3.2
Implementing Secure Network Design (Updated Feb 4, 2019)
19
Computer Science
Professional
11/13/2018

Additional Computer Science Flashcards

 


 

Cards

Term
Data Plane Tier
Definition
-Also known as Forwarding Plane
-Forwards traffic to the next hop along the path to the selected destination
-packets go through the router
-routers/switches
-built to dispose of incoming and outgoing frames and packets
Term
Security Zones
Definition
-Bastion Host
-Screened host gateway
-Screened subnet gateway
Term
Control Plane Tier
Definition
-Config Policy
-Monitor Performance
-Makes decisions about where traffic is sent
-It is the Signalling of the network
-route controller exchanges the topology information with other routers and constructs a routing table
Term
Physical / Logical
Definition
-Connected to Same switch
-Logically connected to different VLAN's
-VLAN's group hosts on different physical switches and locations to the same broadcast domain
-Creates Security Boundaries
-Reduces background chatter
Term
App Tier
Definition
-Contracts
-SLA's
-Northbound interfaces
-Orchestrator
Term
Air Gap Use Case
Definition
-Critical Infrastructure
-SCADA Systems
-Classified Networks
Term
Virtualization
Definition
-Method of Segmenting or Isolating
-Keeps host sandboxed
Term
Screened Subnet Gateway
Definition
-Two screened host gateway devices that isolate the LAN from the Internet, creating a DMZ, between them.
Term
Bastion host
Definition
-a dual-homed device
-No direct routing
-configured to allow only certain types of traffic through while excluding the rest of the traffic
Term
Screened Host Gateway
Definition
A packet-filtering device, usually a router, which communicates only with a designated application gateway inside the secured network. No other traffic is allowed in or out
Term
Air Gap
Definition
Method of isolating a computer or network from the internet or external networks
Term
Security Segmentation Models
Definition
Physical
Logical
Virtualization
Air Gapped
Term
Anywhere on network
Definition
Security Device Placement
-Aggregation Switches
Term
Devices on the Perimeter
Definition
Security Device Placement
-Filters
-Proxies
-Firewall
Term
In front of application servers, web servers
Definition
Security Device Placement
-SSL Accelerators
-Load balancers
-DDoS mitigator or Mitigation Appliance
Term
Located on all parts of the network
Definition
Security Device Placement
-Sensors
-Collectors
Term
Orchestrator
Definition
Signals when additional resources are needed. Scales up or down as needed.
Term
On Switches Everywhere
Definition
Taps and Port Mirror
Term

Remote Attestation

 

Definition

 

 

-Centralized Reporting Function

-Runs inventory and encrypts using TPM and stored securely to HSM

-On boot runs inventory again and compares to stored values

 

Supporting users have an ad free experience!