WGU C836 MULTI COMPREHENSIVE FINAL
TEST PAPER
◉ scanner. Answer: a type of tool that can detect various security
flaws when examining hosts
◉ vulnerability assessment tool. Answer: A tool that is aimed
specifically at the task of finding and reporting network services on
hosts that have known vulnerabilities
◉ Nessus. Answer: A well-known vulnerability assessment tool that
includes a port scanner
◉ exploit framework. Answer: A group of tools that can include
network mapping tools, sniffers, and exploits
◉ exploits. Answer: small bits of software that take advantage of
flaws in software/applications in order to cause them to behave in
ways that were not intended by their creators
,◉ Metasploit, Immunity CANVAS, Core Impact. Answer: Name 3
examples of exploit frameworks
◉ security in network design. Answer: This method of security
involves a well-configured and patched network, and incorporating
elements such as network segmentation, choke points, and
redundancy
◉ network segmentation. Answer: The act of dividing a network into
multiple smaller networks, each acting as its own small network
(subnet)
◉ choke points. Answer: certain points in the network, such as
routers, firewalls, or proxies, where we can inspect, filter, and
control network traffic
◉ redundancy. Answer: a method of security that involves designing
a network to always have another route if something fails or loses
connection
◉ firewall. Answer: a mechanism for maintaining control over the
traffic that flows into and out of our networks
◉ packet filtering. Answer: A firewall technology that inspects the
contents of each packet in network traffic individually and makes a
,gross determination (based on source and destination IP address,
port number, and the protocol being used) of whether the traffic
should be allowed to pass
◉ SPI (Stateful Packet Inspection). Answer: a firewall that can watch
packets and monitor the traffic from a given connection
◉ DPI (Deep Packet Inspection). Answer: a firewall technology that
can analyze the actual content of the traffic that is flowing through
◉ proxy server. Answer: a specialized type of firewall that can serve
as a choke point, log traffic for later inspection, and provides a layer
of security by serving as a single source of requests for the devices
behind it
◉ DMZ (demilitarized zone). Answer: a combination of a network
design feature and a protective device such as a firewall.
Often used for systems that need to be exposed to external networks
but are connected to our own network (such as a web server)
◉ NIDS (Network intrusion detection system). Answer: A system
that monitors network traffic and alerts for unauthorized activity
, ◉ signature-based IDS. Answer: An IDS that maintains a database of
signatures that might signal a particular type of attack and compares
incoming traffic to those signatures
◉ anomaly-based IDS. Answer: an IDS that takes a baseline of
normal network traffic and activity and measures current traffic
against this baseline to detect unusual events
◉ VPN (Virtual Private Network). Answer: an encrypted connection
between two points
◉ SSH (Secure Shell). Answer: protocol used to secure traffic in a
variety of ways, including file transfers and terminal access. uses
RSA encryption (asymmetric encryption)
◉ BYOD (bring your own device). Answer: a phrase that refers to an
organization's strategy and policies regarding the use of personal vs.
corporate devices
◉ MDM (mobile device management). Answer: a solution that
manages security elements for mobile devices in the workplace
◉ kismet. Answer: a well-known Linux sniffing tool used to detect
wireless access points
TEST PAPER
◉ scanner. Answer: a type of tool that can detect various security
flaws when examining hosts
◉ vulnerability assessment tool. Answer: A tool that is aimed
specifically at the task of finding and reporting network services on
hosts that have known vulnerabilities
◉ Nessus. Answer: A well-known vulnerability assessment tool that
includes a port scanner
◉ exploit framework. Answer: A group of tools that can include
network mapping tools, sniffers, and exploits
◉ exploits. Answer: small bits of software that take advantage of
flaws in software/applications in order to cause them to behave in
ways that were not intended by their creators
,◉ Metasploit, Immunity CANVAS, Core Impact. Answer: Name 3
examples of exploit frameworks
◉ security in network design. Answer: This method of security
involves a well-configured and patched network, and incorporating
elements such as network segmentation, choke points, and
redundancy
◉ network segmentation. Answer: The act of dividing a network into
multiple smaller networks, each acting as its own small network
(subnet)
◉ choke points. Answer: certain points in the network, such as
routers, firewalls, or proxies, where we can inspect, filter, and
control network traffic
◉ redundancy. Answer: a method of security that involves designing
a network to always have another route if something fails or loses
connection
◉ firewall. Answer: a mechanism for maintaining control over the
traffic that flows into and out of our networks
◉ packet filtering. Answer: A firewall technology that inspects the
contents of each packet in network traffic individually and makes a
,gross determination (based on source and destination IP address,
port number, and the protocol being used) of whether the traffic
should be allowed to pass
◉ SPI (Stateful Packet Inspection). Answer: a firewall that can watch
packets and monitor the traffic from a given connection
◉ DPI (Deep Packet Inspection). Answer: a firewall technology that
can analyze the actual content of the traffic that is flowing through
◉ proxy server. Answer: a specialized type of firewall that can serve
as a choke point, log traffic for later inspection, and provides a layer
of security by serving as a single source of requests for the devices
behind it
◉ DMZ (demilitarized zone). Answer: a combination of a network
design feature and a protective device such as a firewall.
Often used for systems that need to be exposed to external networks
but are connected to our own network (such as a web server)
◉ NIDS (Network intrusion detection system). Answer: A system
that monitors network traffic and alerts for unauthorized activity
, ◉ signature-based IDS. Answer: An IDS that maintains a database of
signatures that might signal a particular type of attack and compares
incoming traffic to those signatures
◉ anomaly-based IDS. Answer: an IDS that takes a baseline of
normal network traffic and activity and measures current traffic
against this baseline to detect unusual events
◉ VPN (Virtual Private Network). Answer: an encrypted connection
between two points
◉ SSH (Secure Shell). Answer: protocol used to secure traffic in a
variety of ways, including file transfers and terminal access. uses
RSA encryption (asymmetric encryption)
◉ BYOD (bring your own device). Answer: a phrase that refers to an
organization's strategy and policies regarding the use of personal vs.
corporate devices
◉ MDM (mobile device management). Answer: a solution that
manages security elements for mobile devices in the workplace
◉ kismet. Answer: a well-known Linux sniffing tool used to detect
wireless access points