Cisco CCNP Security Core (SCOR) 350-701 flashcards
162 free flashcards. Tap a card to flip it.
Default Deny
Flip cardDefault deny (or implicit deny) is a security principle stating that all access to a resource is forbidden unless explicitly granted. It is commonly implemented in firewalls, access control lists, and user permissions.
- All traffic is blocked unless an explicit rule permits it.
- Minimizes the attack surface.
- Ensures only necessary services are exposed.
Memory trick: Default Deny: The 'default' answer is 'NO' unless I say 'YES'.
Unauthorized Access
Flip cardUnauthorized access refers to gaining entry to a system, network, or data without explicit permission, often by bypassing security controls or exploiting vulnerabilities.
- Involves illicit entry into restricted resources.
- Can lead to data breaches, system compromise, or service disruption.
- Often detected through anomaly detection, log analysis, or IDS/IPS alerts.
Memory trick: If it's not on the list, it's unauthorized access.
Zero Trust - Verify Explicitly
Flip cardThe 'Verify Explicitly' principle of Zero Trust dictates that all access requests must be authenticated and authorized based on all available data points, including user identity, device posture, location, and application context, rather than trusting by default.
- Authenticates and authorizes every access attempt.
- Considers multiple attributes for decision-making.
- Requires continuous monitoring and re-evaluation of trust.
Memory trick: Verify Explicitly: 'V' for 'Validate' everything, every time.
SLAAC Auditing Challenge
Flip cardStateless Address Autoconfiguration (SLAAC) in IPv6 allows hosts to generate their own IP addresses, which can lead to challenges in centrally tracking and auditing assigned addresses for security and inventory management.
- Hosts generate their own IP addresses.
- No central record of IP assignments.
- Complicates auditing and incident response.
Memory trick: IPv6 addresses are like snowflakes; how do you track them all?
ACL Implicit Deny
Flip cardAt the end of every Access Control List (ACL), there is an implicit 'deny any any' statement that blocks all traffic not explicitly permitted by preceding statements.
- Not explicitly visible in the configuration.
- Ensures all unpermitted traffic is dropped.
- Requires careful ordering of permit/deny rules.
Memory trick: Rules are read in order, first match wins, then the silent 'NO'.
IPsec VPN
Flip cardIPsec VPN (Internet Protocol Security Virtual Private Network) is a suite of protocols that provides cryptographic protection for IP communications, commonly used to create secure tunnels between networks (site-to-site VPNs) or remote users and a network (remote-access VPNs).
- Provides confidentiality (encryption), integrity (hashing), and authenticity (authentication).
- Operates at the network layer (OSI Layer 3).
- Uses two main protocols: Authentication Header (AH) and Encapsulating Security Payload (ESP).
- Can be implemented in tunnel mode (for networks) or transport mode (for hosts).
Memory trick: IPsec: 'IP' traffic gets 'SEC'ured for the whole site.
VLAN for Isolation
Flip cardVLANs (Virtual Local Area Networks) can be used to logically segment a network, allowing specific hosts or groups of hosts to be isolated from the rest of the network for security or operational purposes.
- Provides logical segmentation without physical changes.
- Can create 'quarantine' segments for infected hosts.
- Facilitates management access to isolated devices.
Memory trick: Separate your network like a house with many rooms.
RADIUS AAA
Flip cardRemote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users connecting to a network service.
- Widely used for network access (VPNs, 802.1X)
- Supports various authentication methods, including MFA
- Comprehensive accounting records for auditing
- Operates over UDP
Memory trick: RADIUS: Remote Access, Account, Authenticate.
Advanced Persistent Threat (APT)
Flip cardA stealthy and continuous computer hacking process, often orchestrated by a nation-state, targeting a specific entity for business or political motives.
- Highly targeted and sophisticated
- Focus on long-term access and data exfiltration
- Evades traditional security measures
- Uses custom malware and legitimate tools
Memory trick: APT: Advanced, Persistent, Stealthy.
Signature-Based Detection
Flip cardSignature-based detection is a method used by IDS/IPS systems to identify and block threats by comparing network traffic or system activity against a database of known attack patterns or signatures.
- Relies on a database of known attack patterns.
- Effective against known exploits and malware.
- Can be bypassable by polymorphic or zero-day threats.
Memory trick: An IPS finds bad guys by their 'known faces' or 'weird behavior'.
QoS for Application Prioritization
Flip cardQuality of Service (QoS) is a set of technologies that manage network traffic to ensure the performance of critical applications by prioritizing their data over less important traffic.
- Prioritizes critical application traffic.
- Manages bandwidth and latency.
- Ensures availability and performance during congestion.
Memory trick: Traffic needs rules, and some cars are more important.
TACACS+
Flip cardTACACS+ (Terminal Access Controller Access-Control System Plus) is a Cisco proprietary AAA protocol that provides separate authentication, authorization, and accounting services, offering granular command authorization for network devices.
- Uses TCP port 49.
- Encrypts the entire packet body.
- Separates AAA functions, allowing independent control.
- Ideal for granular command authorization on network devices.
Memory trick: TACACS+: 'T' for 'Total' control over 'A'dmin commands.
TACACS+ Command Authorization
Flip cardTACACS+ (Terminal Access Controller Access Control System Plus) is an AAA protocol that provides granular command-level authorization on network devices, allowing administrators to control which specific commands users can execute based on their roles.
- Centralized AAA protocol.
- Strong emphasis on command authorization.
- Separates authentication, authorization, and accounting.
Memory trick: AAA is like a bouncer (Auth), a manager (Authz), and a bookkeeper (Acct).
Defense in Depth
Flip cardDefense in Depth is a security strategy that employs multiple layers of security controls (administrative, technical, physical) to protect an organization's assets. If one layer fails, another layer is there to provide protection.
- Creates redundant security measures.
- Aims to slow down and complicate attacks.
- Applies across physical, technical, and administrative domains.
Memory trick: Defense in Depth: like an onion, layers protect the core.
NAT Overload (PAT)
Flip cardNAT Overload, also known as Port Address Translation (PAT), is a type of NAT that allows multiple internal private IP addresses to share a single public IP address by mapping different source port numbers to distinguish traffic flows.
- Many-to-one mapping (many private IPs to one public IP).
- Uses source port numbers for differentiation.
- Most common for home and small business internet access.
Memory trick: NAT is like a translator; how many people are talking to how many public faces?
Remote-Access VPN
Flip cardA Remote-Access VPN (Virtual Private Network) allows individual users to establish a secure, encrypted connection to a private network from a remote location over a public network like the internet.
- Connects individual users.
- Provides secure tunnels (encryption).
- Supports various client OS via software.
Memory trick: VPNs are like secret tunnels; know who's using them.
DNS Tunneling
Flip cardDNS tunneling is a technique that encapsulates data of other protocols (like IP) within DNS queries and responses, creating a covert communication channel that can bypass firewalls and security controls.
- Used for command and control (C2) or data exfiltration.
- Often characterized by high volumes of queries to non-existent or arbitrary subdomains.
- Difficult to detect with traditional network security tools.
Memory trick: Tunneling: DNS queries are secret tunnels for data.
SDN for Hybrid Cloud Security
Flip cardLeveraging Software-Defined Networking principles to centralize and automate network security policy management and enforcement across both on-premises and cloud infrastructures.
- Centralized control plane for policies
- Automated policy deployment
- Consistent security across heterogeneous environments
Memory trick: SDN: One brain, many networks.
WAF OSI Layer
Flip cardA Web Application Firewall (WAF) primarily operates at Layer 7 (Application Layer) of the OSI model, inspecting and filtering HTTP/HTTPS traffic to protect web applications from specific attacks.
- Inspects HTTP/HTTPS traffic.
- Protects against SQL injection, XSS, etc.
- Understands application-specific syntax and logic.
Memory trick: Each layer has its own guard, but the WAF guards the 'application door'.
IPS False Positive
Flip cardAn IPS false positive occurs when an Intrusion Prevention System incorrectly identifies legitimate network traffic or activity as malicious and takes preventive action, such as dropping packets.
- Leads to disruption of legitimate services.
- Requires careful tuning of IPS policies and signatures.
- A balance between security and availability must be achieved.
Memory trick: Too aggressive IPS: like an overzealous bouncer blocking VIPs.
Remote Access SSL VPN
Flip cardA type of Virtual Private Network (VPN) that uses the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol to create a secure, encrypted connection for individual remote users to access a private network.
- Designed for 'client-to-site' connections.
- Widely supported by web browsers and dedicated clients (e.g., Cisco AnyConnect).
- Uses TCP port 443, making it firewall-friendly.
- Offers strong encryption and authentication options (e.g., certificates, MFA).
Memory trick: For mobile access, SSL is the universal key and shield.
Micro-segmentation (SDN)
Flip cardA network security technique that creates granular security zones for individual workloads (VMs, containers) within a data center, allowing for distinct security policies to be applied to each workload.
- Enforced by Software-Defined Networking (SDN) and network virtualization.
- Policies are attribute-based (e.g., application, OS, user role).
- Reduces the attack surface and limits lateral movement of threats.
Memory trick: Cutting the network into tiny, secure slices for every app.
Cisco Secure Network Analytics (Stealthwatch)
Flip cardA network visibility and security analytics solution that uses NetFlow/IPFIX data to provide comprehensive awareness of network activity, detect advanced threats, and respond to incidents. It builds a baseline of normal behavior to identify anomalies.
- Analyzes network flow data (NetFlow, IPFIX).
- Detects anomalous behavior, insider threats, data exfiltration.
- Provides application visibility and identifies network conversations.
- Integrates with other security tools for automated response.
Memory trick: For tricky traffic, Stealthwatch uncovers the hidden app's path.
Cloud-based DDoS Scrubbing Service
Flip cardA service offered by a third-party provider that diverts an organization's internet traffic during a DDoS attack, 'scrubs' or cleans the malicious traffic, and then forwards only legitimate traffic back to the organization's network.
- Leverages provider's massive bandwidth to absorb attacks.
- Protects against volumetric, protocol, and application-layer attacks.
- Minimizes impact on legitimate traffic and organizational infrastructure.
- Always-on or on-demand deployment models.
Memory trick: To weather the DDoS storm, go to the cloud's big umbrella.
Role-Based Access Control (RBAC) with Centralized Policy
Flip cardAn access control model where permissions are associated with roles, and users are assigned to appropriate roles. When integrated with a centralized policy engine, it enables dynamic, scalable, and consistent access policy enforcement across the network based on identity and context.
- Permissions are granted based on roles, not individual users.
- Centralized policy engine (e.g., NAC) manages roles and permissions.
- Dynamically assigns access based on user, device, and context.
- Reduces administrative overhead compared to static ACLs.
Memory trick: For dynamic access, roles and a central brain are key.
Air-Gapped Network with Data Diode
Flip cardA security architecture where a critical network segment is physically isolated from other networks (air-gapped) and uses a data diode to enforce unidirectional data flow, typically from the secure to the less secure network.
- Provides physical separation for maximum isolation.
- Data diode allows data flow in one direction only.
- Commonly used for highly sensitive OT/ICS environments.
- Prevents inbound cyberattacks.
Memory trick: For OT, think physical separation and one-way streets.
Cisco Talos Reputation Intelligence
Flip cardA security intelligence feed from Cisco Talos that provides real-time reputation scores for IP addresses and URLs, identifying and blocking known malicious sources.
- Focuses on IP addresses and URLs.
- Identifies botnet C2s, phishing sites, and other malicious infrastructure.
- Used for proactive blocking of known bad actors.
Memory trick: Talos feeds help you prevent the bad guys from getting through.
NAT64 and DNS64
Flip cardA combination of IPv6 transition mechanisms that allows IPv6-only clients to communicate with IPv4-only servers. DNS64 synthesizes AAAA records for IPv4-only destinations, and NAT64 translates IPv6 packets to IPv4 packets at a gateway.
- Enables IPv6-only clients to reach IPv4-only servers.
- DNS64 translates IPv4 addresses to IPv6-mapped IPv6 addresses.
- NAT64 performs the actual header translation at a gateway.
- No dual-stack required on client or server.
Memory trick: NAT64 and DNS64 are the interpreters between IPv6-only and IPv4-only worlds.
Virtualized NGFW in Hybrid Cloud
Flip cardLeveraging virtual instances of Next-Generation Firewalls (NGFWs) deployed within public cloud environments, integrated with on-premises security, and managed by a centralized platform to ensure consistent security policy enforcement and visibility across hybrid cloud deployments.
- Extends advanced security capabilities (IPS, app control, URL filtering) to cloud workloads.
- Enables consistent policy enforcement across on-premises and cloud.
- Supports dynamic scaling and automation in cloud environments.
- Managed by a central orchestrator for unified control.
Memory trick: To bridge the cloud and on-prem, use smart, virtual guards.
Web Application Protocols
Flip cardWeb applications primarily use the Hypertext Transfer Protocol (HTTP) and Hypertext Transfer Protocol Secure (HTTPS), both of which are built on top of the Transmission Control Protocol (TCP) for reliable data transfer.
- HTTP and HTTPS use TCP as their transport layer protocol.
- Common TCP ports are 80 (HTTP) and 443 (HTTPS).
- UDP is typically used for connectionless services like DNS or VoIP, not standard web browsing.
Memory trick: Logs tell a story; read the protocol for the real plot twist.
Standard IP ACL Syntax
Flip cardCisco Access Control List (ACL) syntax for filtering IP traffic based on source IP address, destination IP address, protocol, and port numbers.
- ACLs are processed top-down, first match wins.
- An implicit 'deny any any' is at the end of every ACL.
- Wildcard masks are used with source/destination IP addresses.
Memory trick: Access Control Lists: like bouncers for network packets, checking IDs and destinations.
Host-based Intrusion Detection System (HIDS)
Flip cardA security system that monitors and analyzes activity on an individual host (e.g., server, workstation) to detect suspicious behavior, unauthorized changes, or malicious activity.
- Provides granular visibility into file access, process execution, and system calls.
- Crucial for detecting insider threats and advanced persistent threats (APTs).
- Can detect attacks that bypass network-based defenses.
Memory trick: To catch a sneaky threat, know if you're watching the door or inside the house.
QoS Classification and Marking
Flip cardThe initial steps in a Quality of Service (QoS) policy where incoming network traffic is identified (classified) based on various criteria (e.g., source/destination IP, port, application) and then assigned a specific priority or class of service (marked) using fields like DSCP or CoS.
- Classification identifies traffic types.
- Marking tags packets for prioritization by downstream devices.
- Common marking fields: DSCP (IP Layer 3) and CoS (Ethernet Layer 2).
- Typically performed at the network edge (ingress) to ensure end-to-end QoS.
Memory trick: First, identify and tag your traffic; then, manage the flow.
Data Diode
Flip cardA hardware-based network security device that creates an electronically or optically enforced unidirectional data flow between two networks, preventing any data from flowing in the reverse direction.
- Provides absolute physical segregation.
- Commonly used in critical infrastructure (OT/ICS) and high-security environments.
- Eliminates the possibility of reverse data flow or cyberattacks across the boundary.
Memory trick: Critical infrastructure needs a one-way street for data, no U-turns allowed.
802.1X Authentication Server
Flip cardThe 802.1X Authentication Server (e.g., RADIUS server, Cisco ISE) is the central authority that validates user/device credentials and dictates network access policies, including VLAN assignment.
- Receives authentication requests from the Authenticator.
- Validates user/device identity against a database (e.g., Active Directory).
- Makes authorization decisions based on identity, roles, and posture.
- Communicates authorization results (e.g., VLAN, ACLs) back to the Authenticator.
Memory trick: The 'Server Says Yes/No' to network access.
Cisco Secure Client ISE Posture Module
Flip cardThe Cisco Secure Client (AnyConnect) Endpoint Security Module, or ISE Posture module, assesses an endpoint's compliance with security policies before granting VPN or network access.
- Checks for antivirus status, OS updates, firewall, disk encryption.
- Reports posture status to Cisco ASA or Cisco ISE.
- Enforces access based on compliance results.
- Crucial for Zero Trust and secure remote access.
Memory trick: Secure Client's 'Posture Police' ensure device health.
Zero Trust for ICS (Agentless)
Flip cardApplying Zero Trust principles to Industrial Control Systems (ICS) often involves agentless solutions like network micro-segmentation and passive device profiling due to the constraints of OT environments.
- Avoids active agents on sensitive ICS devices.
- Achieves granular control through network-based enforcement.
- Passive profiling identifies devices and their intended communications.
- Critical for preventing lateral movement and unauthorized access in OT.
Memory trick: ICS needs 'Segmented Safety' without 'Agent Aggravation'.
EDR Behavioral Analytics & Forensics
Flip cardEndpoint Detection and Response (EDR) solutions use behavioral analytics to detect suspicious activities and collect forensic data to investigate security incidents on endpoints.
- Detects anomalous process execution, file access, network connections.
- Collects detailed logs and artifacts for incident investigation.
- Helps identify root cause, scope, and method of attacks.
- Crucial for advanced threat detection and response.
Memory trick: EDR 'Detects, Dissects, and Documents' endpoint threats.
Guest Wi-Fi Isolation
Flip cardA security design principle for wireless networks that ensures guest users are segmented from the corporate network and often from each other, while still providing internet access.
- Prevents unauthorized access to internal resources.
- Reduces the attack surface from untrusted devices.
- Typically involves VLANs, client isolation, and firewall rules.
Memory trick: Guests get their own isolated, firewalled lane to the internet.
Network Intrusion Prevention System (NIPS)
Flip cardA network security device that monitors network traffic for malicious activity, logs information about such activity, attempts to block it, and reports it.
- Operates in-line, actively blocking threats.
- Uses signatures, anomaly detection, and policy enforcement.
- Protects against various attacks like brute-force, DoS, exploits.
Memory trick: Detect and Prevent, stay vigilant and defend.
RADIUS Tunnel-Private-Group-ID
Flip cardThe RADIUS `Tunnel-Private-Group-ID` attribute (Attribute 81) is used by an Authentication Server to dynamically assign a client to a specific VLAN during 802.1X authentication.
- Standard RADIUS attribute (Attribute 81).
- Carries the VLAN ID or name.
- Sent in an Access-Accept message from the RADIUS server.
- Received by the Authenticator (switch) to place the client in the specified VLAN.
Memory trick: Tunnel-Private-Group-ID is the 'VLAN Express Ticket'.
Zero Trust: Verify Explicitly
Flip cardThe 'Verify Explicitly' Zero Trust principle requires all access requests to be authenticated and authorized based on all available data points, continuously and dynamically.
- No implicit trust granted to any user or device.
- Access decisions are dynamic and context-aware.
- Continuously re-evaluates access based on changing conditions (location, posture, etc.).
- Applies to all resources, regardless of network location.
Memory trick: Zero Trust says 'Explicitly Verify Everything, Always'.