This Layer 2 technology groups switch ports logically to separate broadcast domains and map them to distinct Layer 3 IP subnets.
What is a Virtual Local Area Network (VLAN)?
This basic type of firewall inspects only Layer 3 and Layer 4 packet headers without tracking the state of connections.
What is a packet filtering (stateless) firewall?
This passive device or switch feature copies network traffic from a physical port to an intrusion detection sensor without interfering with the original cable path.
What is a Test Access Point (TAP) or Port Mirror (SPAN)?
This remote administration protocol uses public key cryptography to encrypt terminal management sessions on TCP port 22.
What is Secure Shell (SSH)?
This dedicated server acts as a single, hardened intermediary host that administrators must log into before connecting to internal production systems.
What is a jump server (or bastion host)?
This physical network topology design restricts a system completely by disconnecting it from all other external and internal networks, requiring manual updates via removable media.
What is an air gap (physical isolation)?
This table is maintained by a Layer 4/5 firewall to track active two-way TCP handshakes and determine whether incoming packets are new or established.
What is a state table?
If a network security appliance fails, this operational mode ensures continuous network availability by allowing all traffic to pass through uninspected.
What is fail-open?
In an IPsec VPN, this specific protocol header provides data encryption, confidentiality, and integrity, unlike Authentication Header (AH) which provides integrity only.
What is Encapsulation Security Payload (ESP)?
Dedicated computers that are strictly reserved for administrative tasks and isolated from standard email and web browsing are known as these.
What are Secure Administrative Workstations (SAWs)?
When designing security zones, this perimeter network segment contains public-facing hosts (such as web and mail servers) to isolate them from internal private databases.
What is a Screened Subnet (or Demilitarized Zone / DMZ)?
Unlike standard network firewalls, this specialized security tool inspects Layer 7 payloads specifically for web application attacks such as SQL injection and XSS.
What is a Web Application Firewall (WAF)?
This is the operational distinction between an IDS and an IPS when an exploit signature is detected.
What is passive logging/alerting (IDS) versus active inline blocking/mitigation (IPS)?
This IPsec operational mode encrypts the entire original IP packet and adds a new IP header, making it suitable for site-to-site connections across the public internet.
What is tunnel mode?
Managing network devices using a physical console cable or a dedicated, isolated management VLAN completely separate from standard production traffic is known as this.
What is Out-of-Band (OOB) management?
In an IEEE 802.1X implementation, these are the three specific roles involved in network port authentication.
What are the Supplicant, Authenticator (switch), and Authentication Server (RADIUS)?
A security appliance combines a traditional firewall, intrusion prevention, anti-malware, spam filtering, and content filtering into a single manageable platform.
What is a Unified Threat Management (UTM) (or NGFW)?
An inline proxy deployed between clients and the internet that intercepts outbound web sessions without requiring any endpoint browser configuration is known as this type of proxy.
What is a transparent proxy?
During Phase 1 of the Internet Key Exchange (IKE) negotiation, this data structure is formed between peers to authenticate identities and establish the management tunnel.
What is a Security Association (SA)?
This protocol allows a central directory (like Active Directory) to handle authentication, authorization, and accounting for network switches and VPN gateways.
What is RADIUS (or TACACS+)?
An administrator notices that an access switch drops incoming packets when an unauthorized MAC address connects to an interface. Which port security feature was implemented, and what protocol framework passes the user credentials over LAN?
What are MAC filtering/limiting and EAPoL (EAP over LAN)?
A network engineer must deploy a firewall policy that allows internal clients to reach the web while blocking uninitiated inbound traffic. What TCP keyword or mechanism ensures returning packets are permitted through an ACL?
What is the established parameter (stateful inspection)?
An organization places a firewall appliance directly inline on a link, but configures it to operate transparently at Layer 2 without an assigned IP default gateway. What is this firewall architecture called?
What is a bridged (or transparent) firewall?
A remote worker accesses internal corporate web applications over HTTPS via a web browser without installing dedicated client software. What remote access architecture is being leveraged?
What is clientless / HTML5 remote desktop (or SSL/TLS portal)?
When connecting via SSH to a newly provisioned jump host for the first time, what cryptographic artifact does the client inspect and cache to prevent Man-in-the-Middle attacks?
What is the server's public host key (or key fingerprint)?