Network Security unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
On-path attack
DDoS mitigation
Rogue access point and evil twin
Wireless security standards
Network segmentation
Screened subnet (DMZ)
Penetration testing
Defense in depth
Denial-of-service
Chain of custody
Stateful inspection
Port security as one layer of defense
Short answer 1. Define or explain: ARP poisoning
3 ptsShort answer 2. Define or explain: MAC filtering limits
3 ptsShort answer 3. Define or explain: Site-to-site vs remote-access VPN
3 ptsShort answer 4. Define or explain: Least privilege on a network
3 ptsFree response
6 ptsExplain the principle of defense in depth as applied to a network, giving three distinct layers.
Explain what a VPN provides and identify one thing it does not protect against.
Explain the difference between authentication and authorization, and give an example of each.
Explain what 802.1X provides and where it is deployed.
Explain how a rogue access point threatens a network and describe one control that detects or prevents it.
Explain what network address translation does and state whether it should be considered a security control.