Securing Networks unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
Distributed denial-of-service (DDoS)
Next-generation firewall
ARP poisoning
Stateful firewall
Port scanning
SIEM
Rogue access point
DNS poisoning
DMZ (screened subnet)
SSID broadcast
Lateral movement
Access control list (ACL)
Short answer 1. Define or explain: On-path (man-in-the-middle) attack
3 ptsShort answer 2. Define or explain: Network segmentation
3 ptsShort answer 3. Define or explain: Deauthentication attack
3 ptsShort answer 4. Define or explain: Botnet
3 ptsFree response
6 ptsA company operates a single flat network. Guest Wi-Fi, employee workstations, printers, and the finance database server all share one address range, and the perimeter firewall contains a rule permitting any source to reach any destination on any port, which was added during a troubleshooting session two years ago.
Explain network segmentation and describe how VLANs would be applied in this environment.
Explain the default-deny principle and what is wrong with the existing firewall rule.
Explain the difference between a stateless access control list and a stateful firewall.
Explain what a DMZ is and identify what kind of system belongs in one.
Explain how a zero trust model differs from a traditional perimeter model.
Explain the difference between an intrusion detection system and an intrusion prevention system.