Domain 4 · 13% of the exam
Communication and Network Security
Security professionals must understand the principles of secure system design and the different tools and techniques that can be used to protect information and systems. This includes not only technical controls, such as cryptography and access controls, but also security models, testing methodologies, and the measures necessary to protect systems and equipment from physical threats.
Learning objectives
- Understand the role of the ISO OSI 7-Layer and TCP/IP models in internetworking and data communications.
- Describe the architectural characteristics, relevant technologies, protocols, and security threats associated with each layer in the OSI model.
- Describe the evolution of methods to secure IP communications protocols.
- Contrast the security considerations of network virtualization with physical networks.
- Describe key software-defined networking (SDN) concepts.
- Describe the evolution of and security implications for key network devices.
- Describe the architecture and design of computer hardware security.
- Evaluate the security issues and implications of communications in traditional and VolP infrastructures and of remote computing tools.
Key topics
- Secure Design Principles in Network Architectures
- Secure Network Components
- Secure Communication Channels
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01OSI Layer 1 - Physical Layer - Network TopologiesA network topology addresses the ways systems interconnect and relate to each other. Each topology is a shape pattern that describes the direct connections each node has with others in its network and which nodes must communicate through other nodes).8 slides · 4 min read
- 02Bound or Wired MediaThe wired media utilized within the Physical Layer of the Open Systems Interconnection (OSI) model spans various strands and gauges of copper along with plastics and glass.7 slides · 3 min read
- 03Threat Modeling and InternetworkingThreat modeling for internetworking identifies potential risks across connected systems, guiding security measures to protect data, services, and infrastructure.3 slides · 1 min read
- 04Threat Modeling and Internetworking - Kill ChainsIn 2014, a committee report to the U.S. Senate offered an operationally realistic model that applied classical military doctrine to cybersecurity attacks.4 slides · 2 min read
- 05Secure ProtocolsTo address weaknesses in the transmission of information across networks, a variety of secure protocols have been developed.8 slides · 4 min read
- 06Legacy Remote AccessLegacy remote access tools often lack encryption and robust authentication, making them unsuitable for remote and hybrid teams and today's sophisticated cyber threats.5 slides · 3 min read
- 07Virtual Private Networks (VPNs) through TunnelingPoint-to-Point Tunneling Protocol (PPTP)| is a legacy protocol that relies on Generic Routing Encapsulation (GRE) to build the tunnel between the endpoints.5 slides · 3 min read
- 08Port Address Translation, Proxy Firewall, Proxy TypesAn extension to network address translation (NAT), which translates all addresses to one externally routable IP address, is to use port address translation3 slides · 2 min read
- 09Multilayer and Converged ProtocolsMultilayer and converged protocols integrate diverse communication layers, streamlining data exchange while demanding careful design to maintain performance, compatibility, and security.2 slides · 2 min read
- 10Multimedia CollaborationPeer-to-peer (P2P) applications are often designed to open an uncontrolled channel through network boundaries (normally through tunneling).3 slides · 1 min read
- 11Virtual Applications and DesktopsVirtual terminal service is a tool frequently used for remote access to server resources. Virtual terminal services allow the desktop environment for a server to be exported to a remote workstation.2 slides · 1 min read
- 12Bluetooth & WiFi Wireless ProtocolsPrimarily associated with computer networking, Wi-Fi uses the IEEE 802.11x specification to create a wireless local-area network either public or private. A Wi-Fi network consists of a wireless connection to wireless access point (WAP) that is normally…9 slides · 4 min read
- 13Wi-Fi Standards, Bluetooth, Securing WAPs, Using Captive Portals, Wireless AttacksWi-Fi Standards, Bluetooth, Securing WAPs, Using Captive Portals, Wireless Attacks6 slides · 5 min read
- 14Network Access Control (NAC) DevicesNetwork access control devices manage and enforce security policies by controlling which users or devices can access a network, based on authentication, compliance, and authorization rules.5 slides · 4 min read
- 15Third-Party ConnectivityThird-party connectivity introduced external systems into networks, requiring strict controls, monitoring, and agreements to manage trust and reduce security risks.2 slides · 1 min read
- 16NAC FrameworksCurrently there are a number of vendors and consortiums working on developing standards to provide interoperability for NAC devices and solutions, with perhaps the biggest three being:2 slides · 1 min read
- 17NAC Best PracticesBefore deploying NAC devices, it is important to do your research.3 slides · 1 min read
- 18Telecommunications for Internet AccessTraditional telecommunications companies have used several Layer 1 technologies to provide connectivity for IP protocols.8 slides · 5 min read
- 19802.1X NAC802.1X is a port-based network access control (or PNAC) protocol, which provides the authentication control for devices attempting to connect to both local area networks (LANs) and wireless local area networks (or WLANs).3 slides · 1 min read
- 20Network Function Virtualization (NFV)The modern virtualization of networks and the associated technology is called network function virtualization (NFV) or alternately referred to as virtual network function.2 slides · 1 min read
- 21Zero Trust vs Trust, but VerifyBoth the OSI 7-Layer and TCP/IP models and protocols evolved during an era of small, less powerful computing and communications hardware. Security as a result was often allocated to the Applications Layer (or, at most, to apps that could work in tandem…9 slides · 2 min read
- 22Case Study - TargetCase studyIn 2013, the Target corporation experienced a major data breach that compromised the personal and financial information of millions of its customers.4 slides · 1 min read
- 23Case Study - TalkTalkCase studyThe TalkTalk data breach of 2015 marked a significant cybersecurity incident targeting the UK-based telecommunications giant. Exploiting vulnerabilities in TalkTalk's website through an SQL injection attack, hackers gained unauthorized access to a database…4 slides · 1 min read
- 24Remote Access and Remote Meeting TechnologyThe adoption of remote tools has grown rapidly to support flexible, collaborative work environments for distributed teams.4 slides · 2 min read
- 25Telecommuting and Screen ScraperCommon issues such as visitor control, physical security, and network control are almost impossible to address with teleworkers. Strong VPN connections between the teleworker and the organization need to be established, and full device encryption should be…3 slides · 1 min read
- 26Voice over Internet Protocol (VoIP)Voice over Internet Protocol (VolP) is a technology that allows you to make voice calls using a broadband internet connection instead of a regular (or analog) phone line.5 slides · 2 min read
