SY0-701 Lesson 5: Secure Enterprise Network
Architecture Exam | Questions with 100% Correct
Answers | Verified | Latest Update 2026
Save
Terms in this set (81)
on premises network A private network facility that is owned and
operated by an organization for use by its
employees only.
logical segmentation Network topology enforced by switch, router, and
firewall configuration where hosts on one network
segment are prevented from or restricted in
communicating with hosts on other segments.
Internet Protocol (IP) Network (Internet) layer protocol in the TCP/IP
suite providing packet addressing and routing for
all higher-level protocols in the suite.
virtual LAN (VLAN) A logical network segment comprising a broadcast
domain established using a feature of managed
switches to assign each port a VLAN ID. Even
though hosts on two VLANs may be physically
connected to the same switch, local traffic is
isolated to each VLAN, so they must use a router to
communicate.
, security zones An area of the network (or of a connected
network) where the security configuration is the
same for all hosts within it. In physical security, an
area separated by barriers that control entry and
exit points.
attack surface The points at which a network or application
receive external connections or inputs/outputs that
are potential vectors to be exploited by a threat
actor.
port security Preventing a device attached to a switch port from
communicating on the network unless it matches a
given MAC address or other protection profile.
MAC filtering Applying an access control list to a switch or
access point so that only clients with approved
MAC addresses can connect to it.
IEEE 802.1X A standard for encapsulating EAP communications
over a LAN (EAPoL) or WLAN (EAPoW) to
implement port-based authentication.
Supplicant In EAP architecture, the device requesting access
to the network.
Authenticator A PNAC switch or router that activates EAPoL and
passes a supplicant's authentication data to an
authenticating server, such as a RADIUS server.
Architecture Exam | Questions with 100% Correct
Answers | Verified | Latest Update 2026
Save
Terms in this set (81)
on premises network A private network facility that is owned and
operated by an organization for use by its
employees only.
logical segmentation Network topology enforced by switch, router, and
firewall configuration where hosts on one network
segment are prevented from or restricted in
communicating with hosts on other segments.
Internet Protocol (IP) Network (Internet) layer protocol in the TCP/IP
suite providing packet addressing and routing for
all higher-level protocols in the suite.
virtual LAN (VLAN) A logical network segment comprising a broadcast
domain established using a feature of managed
switches to assign each port a VLAN ID. Even
though hosts on two VLANs may be physically
connected to the same switch, local traffic is
isolated to each VLAN, so they must use a router to
communicate.
, security zones An area of the network (or of a connected
network) where the security configuration is the
same for all hosts within it. In physical security, an
area separated by barriers that control entry and
exit points.
attack surface The points at which a network or application
receive external connections or inputs/outputs that
are potential vectors to be exploited by a threat
actor.
port security Preventing a device attached to a switch port from
communicating on the network unless it matches a
given MAC address or other protection profile.
MAC filtering Applying an access control list to a switch or
access point so that only clients with approved
MAC addresses can connect to it.
IEEE 802.1X A standard for encapsulating EAP communications
over a LAN (EAPoL) or WLAN (EAPoW) to
implement port-based authentication.
Supplicant In EAP architecture, the device requesting access
to the network.
Authenticator A PNAC switch or router that activates EAPoL and
passes a supplicant's authentication data to an
authenticating server, such as a RADIUS server.