Terminology
Acronyms
Designing with Security in Mind
Misc.
Networks
100

An _________  ___________ involves taking an action based on an attack or threat

A response generated in real time.

Active response

100

DLP

Data loss prevention

100

A physical and logical depiction of your network that includes methods, security, and technologies

Security topology

100

Is the raw information that the IDS or IPS uses to detect
suspicious activity.

Data Source

100

An ______  _________ can technically be used for either a wired or wireless connection, in reality the term is almost exclusively associated with a wireless-enabling device today.

AP

Access Point

200

Variations from normal operations.

Looks for things outside the ordinary

Anomalies

200

HIDS

A host-based intrusion detection system

200

One of the first lines of defense in a network

Firewalls

200

Is the component or process the operator uses to manage the IDS or IPS.

Manager

200

Detects and monitors the network for anomalies and detects and logs only

NIDS

300

This system works by looking for deviations from a pattern of normal network traffic.

Anomaly-detection IDS (AD-IDS)

300

NIDS

A network-based intrusion detection system. An NIPS is an intrusion prevention system. Unlike an HIDS/HIPS, an NIDS/NIPS scans an entire network
segment

300

Configurations in a router or firewall that determine what is allowed in (in terms of traffic, data, applications, or whatever other term for criteria you want to use) and what is left out

Access control lists (ACLs)

300

Type of detection that looks for variations in behavior
such as unusually high traffic, policy violations, and so on.

Behavior-Based Detection

300

Focuses on not only detecting anomalies on the network but focused on protecting the network as well

NIPS

400

A collection of computer networks that agree on standards of operation, such as security standards

Federation

400

IPSec

Internet Protocol Security

400

An all-in-one appliance,

Unified threat management

400

_________-________ __________is a system that acts based on the digital signature it sees and offers no repudiation to increase the integrity of a message.

Signature-Based Detection

400

You’ve been notified that you’ll soon be transferred to another site. Before you leave,
you’re to audit the network and document everything in use and the reason why it’s
in use. The next administrator will use this documentation to keep the network
running. Which of the following protocols isn’t a tunneling protocol but is probably
used at your site by tunneling protocols for network security?
A. IPSec
B. PPTP
C. L2TP
D. L2F

IPsec

500

______ _________ _________ __________- is an intrusion detection system that monitors the computer infrastructure on which it is installed, analyzing traffic and logging malicious behavior. An HIDS gives you deep visibility into what's happening on your critical security systems ...

Works to identify and log changes in the system.  

Passive

HIDS

Host Intrusion Detection System
500

SIEM



Security information and event management

500

a private network connection that occurs through a
public network

A virtual private network (VPN)

500

Which device stores information about destinations in a network (choose the best
answer)?

A. Hub
B. Modem
C. Firewall
D. Router


D. Router

500

Which of the following can be implemented as a software or hardware solution and is
usually associated with a device—a router, a firewall, NAT, and so on—used to shift a
load from one device to another?

A load balancer

600

An authentication protocol developed at MIT that uses tickets for authentication.

Kerberos

600

SSL

Secure Sockets Layer

600

The _______________ is the person responsible for setting the security policy for an organization and is responsible for making decisions about the deployment
and configuration of the IDS

Administrator

600

Upper management has suddenly become concerned about security. As the senior network administrator, you are asked to suggest changes that should be
implemented. Which of the following access methods should you recommend if the technique to be used is one that is primarily based on preestablished access and can’t be changed by users?

A. MAC
B. DAC
C. RBAC
D. Kerberos


A. MAC

Mandatory Access Control

600

involves blocking websites (or sections of websites) based solely on the URL, restricting access to specified websites and certain web-based applications

URL filtering

700

 Unlike an HIDS/HIPS, an ____ ______ ______ _______ scans an entire network segment.

Passive

NIDS Network Intrusion Detection System

700

NAC

network access control

700

Is a message from the analyzer indicating that an event of interest has
occurred.

Alert

700

You’ve been assigned to mentor a junior administrator and bring her up to speed
quickly. The topic you’re currently explaining is authentication. Which method uses
a KDC to accomplish authentication for users, programs, or systems?

A. CHAP
B. Kerberos
C. Biometrics
D. Smartcards


Kerberos

700

Works by looking at the data that is coming in. Microsoft included content filtering in some versions of their browsers (Internet Explorer and Microsoft Edge), which could be configured using Content Advisor.


Content inspection

800

A tool that enumerates your network and provides a map of the network.

Network scanner

800

ACL

access control list

800

___________  __________also called packet sniffers, are some of the most common tools used
by network administrators.

Analyzer

800

Replaced SSL

TLS (Transport Layer Security)

800

Looks for variations in behavior such as unusually high traffic, policy violations, and so on

Behavior-Based Detection