100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

SANS SEC401 LATEST 2024 GRADED A+

Rating
-
Sold
-
Pages
106
Grade
A+
Uploaded on
13-04-2024
Written in
2023/2024

SANS SEC401 LATEST 2024 GRADED A+ Conceptual Design (network architecture) Includes the core components of a network architecture Will consider OS platforms, server services, critical core operational functions, etc. Helps to understand the overall purpose the network ('WHY' we have it and the "WHAT' it helps us to achieve) May utilize the concept of "closed-box" diagramming TTP Tactics Techniques Procedures Logical design (network architecture) Represents the logical functions in the system Putting the conceptional design on paper Maps the components of the conceptual design via the use of a network diagram Next parts of the architecture understanding will leverage and build upon this design step Uses icons to depict workstations servers printers routers switches and other devices connected to the network Physical design (network architecture) Builds upon the logical design by providing detailed aspects of the network components Details might include: versions, patch levels, hardening configurations, risk categorization, etc. Physical design also considers physical risks such as network cable location, risk of communication interception, etc. Physical security can betray logical security controls Details include OS version, patches, hardening configurations, risks, physical security Communication Flow Understanding Who accesses data ? When (at what times) data is accessed ? How much data is accessed ? Will lead to the development of a baseline - knowing normal allows abormal to stand out. Never a 'one and done'. Continual updating is necessary. Threat Agents Opportunistic Organized cyber crime Advanced Persistent Threats (nation states) Attacks Against Routers (5 examples) Denial of Service Distributed Denial of Service Packet Sniffing Packet Misrouting Routing Table Poisoning Attacks against switches (5 examples) CDP Information Disclosure MAC Flooding DHCP Manipulation STP Manipulation VLAN Hopping CDP Information Disclosure Cisco Discovery Protocol is used for switches to communicate about other devices are discoverable on the network. Exploiting this protocol would give information about types and versions of switches, OS, usernames and administrative accounts on the switches, etc. MAC Flooding Flooding the network with fake Media Access Control (MAC) addresses may degrade the switch and force it into downgrading into a hub, giving the attackers access to the overall network. DHCP Manipulation Dynamic Host Configuration Protocol is used to communicate the network configuration to other devices on the network. An attacker could monitor this protocol and respond to DHCP requests sooner than the intended recipient, placing the attacker's device in the middle of legitimate network traffic - a type of Machine in the Middle position. STP Manipulation Spanning Tree Protocol is used to ensure that switches do not get stuck in a switch loop. The protocol is similar to CDP and the attack is similar - the manipulation could lead a network reconfiguration to cause a DoS or a MiTM. VLAN Hopping Virtual Local Area Network is a way for switches to segment a network into different areas for security purposes. A VLAN hopping attack fools the VLAN into allowing packets into a prohibited VLAN segment. Physical Topology How devices are physically connected together How communications are sent over the physical connection (electrical signaling, pulses of light, radio, etc.) Logical Topology How communication is logically formed prior to transmission Ethernet Most common communication mechanism on networks worldwide Uses CSMA/CD (Carrier Sense with Multiple Access / Collision Detection) that is, it listens to ensure only one station communicates at a time and monitors the transitions to detect collisions. Segmentation (network design)

Show more Read less
Institution
SANS SEC401
Course
SANS SEC401











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
SANS SEC401
Course
SANS SEC401

Document information

Uploaded on
April 13, 2024
Number of pages
106
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

CA$18.48
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
StellarScores Western Governers University
Follow You need to be logged in order to follow users or courses
Sold
1945
Member since
2 year
Number of followers
867
Documents
21200
Last sold
15 hours ago
Your Academic Hub: Documents, Study Guides, Summaries, Essays, and Exclusive Package Deals.

Welcome to my comprehensive academic resource store! At my online hub, I offer a vast array of meticulously crafted documents, study guides, summaries, and essays to support your educational journey. I understand the value of accuracy and completeness, which is why all my materials are verified and kept up-to-date with the latest versions. But that's not all! I also offer exclusive package deals and bundles to provide you with cost-effective solutions for your academic needs. Whether you're a student looking for study aids or seeking in-depth knowledge, my store is your one-stop destination for reliable, top-quality materials that can propel your learning experience to new heights. Explore my offerings and unlock the keys to academic success today!

Read more Read less
4.0

456 reviews

5
249
4
81
3
63
2
24
1
39

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions