Network Security Appliances
Secure Remote Access & VPNs
Network Architecture & Segmentation
Administrative Access & Device Management
Infrastructure Trade-offs & Operations
Final Jepordy
100

A hardware splitter placed directly into a physical cable line that captures all frames without dropping packets under heavy load.

What is a Test Access Point (TAP)?

100

The legacy tunneling protocol that is now considered obsolete and insecure for modern enterprise remote access deployments.

What is Point-to-Point Tunneling Protocol (PPTP)?

100

An isolated Layer 2 broadcast domain assigned a numeric ID between 2 and 4,094 on a switch.

What is a Virtual Local Area Network (VLAN)?

100

A dedicated, hardened workstation stripped of unnecessary software and denied general internet access, used solely for managing network appliances.

What is a Secure Administrative Workstation (SAW)?

100

A system's ability to automatically self-heal and return to an operational state following a failure without human intervention.

What is Resilience?

100

Final Jepordy Topic

Secure Architecture Protocols

200

A device that intercepts, deconstructs, inspects, and rebuilds outbound web packets before forwarding them on behalf of internal clients.

What is a Forward Proxy?

200

A clientless remote access technology using HTML5 canvas and WebSockets to render desktop sessions directly inside a standard web browser.

What is an HTML5 VPN (or Clientless Remote Desktop Gateway)?

200

A network topology practice that groups hosts and resources into distinct zones based on shared security requirements and access control levels.

What is Zone-Based Topology (or Security Zones)?

200

A hardened intermediary server placed inside a secure zone or DMZ that administrators connect to before accessing internal production servers.  

What is a Jump Server (or Bastion Host)?  

200

The risk management strategy utilized when signing a service contract with a cloud provider that enforces financial penalties for downtime.

What is Risk Transference?

200

During an IPsec negotiation, this specific two-phase framework first establishes an encrypted management channel using Diffie-Hellman and digital certificates or pre-shared keys, before negotiating the specific security associations used for payload transit.

What is Internet Key Exchange (IKE)?

300

An active network security appliance placed in-line to detect malicious traffic and automatically take action, such as sending session resets or shunning IP addresses.

What is an Intrusion Prevention System (IPS)?

300

The transport protocol used in DTLS to reduce latency and enhance performance for real-time voice and video traffic.

What is UDP (User Datagram Protocol)?

300

The two CIA triad principles that take highest priority when architecting protections for high-value data assets such as databases and file systems.

What are Confidentiality and Integrity?

300

Management access achieved via dedicated physical serial console ports or physically isolated management VLANs rather than the production data path.

What is Out-of-Band (OOB) Management?

300

An on-premises architecture limitation where expanding capacity requires substantial upfront capital expenses and physical renovations like building rewiring.

What is Limited Scalability (or High Capital Cost)?

400

A dedicated hardware appliance or software feature placed in front of web servers to distribute incoming traffic, mitigate DoS attacks, and route around failed nodes.

What is a Load Balancer?

400

The key exchange version that introduces native EAP authentication, simplified setup, and MOBIKE multihoming support for mobile devices.

What is IKEv2?

400

The sum total of all potential vulnerabilities and points where an unauthorized user or threat actor can access systems or extract data.

What is the Attack Surface?

400

The port-based network access control standard that uses EAP and RADIUS to authenticate endpoints before granting network switch access.

What is IEEE 802.1X?

400

The protocol in IPv6 that replaces IPv4's Address Resolution Protocol (ARP) to map logical IP addresses to Layer 2 MAC addresses.

What is Neighbor Discovery (ND)?

500

An all-in-one security appliance popular with SMBs that consolidates firewalls, antimalware, IPS, and content filtering into a single box, though it introduces a single point of failure.

What is Unified Threat Management (UTM)?

500

The IPsec protocol that provides data confidentiality, integrity, and authentication by encrypting payload data and adding padding and an ICV.

What is Encapsulating Security Payload (ESP)?

500

A complete physical isolation technique where a critical system or network has zero wired or wireless connections to any external network.

What is Air-Gapping?

500

The device failure state mode that shuts off all traffic to preserve confidentiality and integrity when a hardware fault or power outage occurs.

What is Fail-Closed?

500

A firewall inspection technique operating at Layer 7 that analyzes application protocol structures and raw payloads to catch hidden threats and verify protocol compliance.

What is Deep Packet Inspection (DPI)?