• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 144 pages
Exam (elaborations)

GSEC Questions and Correct Answers the Latest Update

Document preview thumbnail
Preview 4 out of 144 pages

conceptual design high level design that includes core components of network architecture | 'black box' I/O | legal, environmental safety | customer experience | multidisciplinary logical design depicts how data flows across different devices in network | detailed, rather than abstract network diagram | services, application names | for developers and security architects | shows servers workstations routers firewalls... physical design last before implementation | all known details | physical components and connections | OS versions communications flow dictated by logical design, shows how data flows in and out of the network | informs threat model; attack surface and vectors; estimate impact; determines defense intellectual property (IP) dictated by logical architecture | key is reduce number or locations where present; subject to copyright router TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today! | Thank You for Choosing Us! © 2024 TestTrackers Customer Support: [] Resources & Updates: [Testtrackers - Stuvia US] Your Success is Our Mission! device that connects different networks together internal and external | forwards data packets between computer networks | operates at OSI L3, handles packets switch networking device that connects computers together to form physical and virtual networks | handles frames at OSI L2 Kismet Linux WLAN sniffer completely passive used for vulnerability assessment and intrusion detection threat enumeration list threat agents | list attack methods | list system-level objectives threat agents (3) human or not | organized crime | espionage | hactivist Advanced Persistent Threat (APT) An organized group of attackers who are highly motivated, skilled, and patient. They are often sponsored by a government, are focused on a specific target, and will continue attacking for a very long time until they achieve their goal. DoS TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today! | Thank You for Choosing Us! © 2024 TestTrackers Customer Support: [] Resources & Updates: [Testtrackers - Stuvia US] Your Success is Our Mission! An availability attack, to consume resources to the point of exhaustion; Denial of Service; flood of ICMP requests targets router takes down server DDoS Denial of service attack committed using many computers, usually zombies on a botnet. packet sniffing capture network traffic for analysis | no longer requires physical access to network due to prevalence of wifi packet misroute malware on rou

Content preview

TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today!



GSEC Questions and Correct Answers the
Latest Update
conceptual design

✓ high level design that includes core components of network architecture | 'black box' I/O
| legal, environmental safety | customer experience | multidisciplinary



logical design

✓ depicts how data flows across different devices in network | detailed, rather than abstract
network diagram | services, application names | for developers and security architects |
shows servers workstations routers firewalls...



physical design

✓ last before implementation | all known details | physical components and connections |
OS versions



communications flow

✓ dictated by logical design, shows how data flows in and out of the network | informs
threat model; attack surface and vectors; estimate impact; determines defense



intellectual property (IP)

✓ dictated by logical architecture | key is reduce number or locations where present; subject
to copyright



router



|
✓ Thank You for Choosing Us! ✓ Resources & Updates: [Testtrackers - Stuvia US]
✓ © 2024 TestTrackers ✓ Your Success is Our Mission!
✓ Customer Support: [+254707240657]

, TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today!


✓ device that connects different networks together internal and external | forwards data
packets between computer networks | operates at OSI L3, handles packets



switch

✓ networking device that connects computers together to form physical and virtual networks
| handles frames at OSI L2



Kismet

✓ Linux WLAN sniffer completely passive used for vulnerability assessment and intrusion
detection



threat enumeration

✓ list threat agents | list attack methods | list system-level objectives



threat agents (3)

✓ human or not | organized crime | espionage | hactivist



Advanced Persistent Threat (APT)

✓ An organized group of attackers who are highly motivated, skilled, and patient. They are
often sponsored by a government, are focused on a specific target, and will continue
attacking for a very long time until they achieve their goal.



DoS




|
✓ Thank You for Choosing Us! ✓ Resources & Updates: [Testtrackers - Stuvia US]
✓ © 2024 TestTrackers ✓ Your Success is Our Mission!
✓ Customer Support: [+254707240657]

, TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today!


✓ An availability attack, to consume resources to the point of exhaustion; Denial of Service;
flood of ICMP requests targets router takes down server



DDoS

✓ Denial of service attack committed using many computers, usually zombies on a botnet.



packet sniffing

✓ capture network traffic for analysis | no longer requires physical access to network due to
prevalence of wifi



packet misroute

✓ malware on router sends traffic to evil location or causes routing loops DoS or network
congestion



XSS

✓ Cross-site scripting. Attacker redirects users to malicious websites, steal cookies. E-mail
can include an embedded HTML image object or a JavaScript image tag as part of a
malicious cross-site scripting attack. Prevent with input validation.



CSRF

✓ Cross-Site Request Forgery--Third-party redirect of static content within the security
context of a trusted site.



SYN flood




|
✓ Thank You for Choosing Us! ✓ Resources & Updates: [Testtrackers - Stuvia US]
✓ © 2024 TestTrackers ✓ Your Success is Our Mission!
✓ Customer Support: [+254707240657]

, TestTrackers: Unlock Your Exam Potential! | Quality Practice Materials | Boost Your Confidence Today!


✓ A type of DoS where an attacker sends a large amount of SYN request packets to a
server in an attempt to deny service.



TCP reset

✓ attacker sniffs target traffic the spoofs packet with RST flag set to end session



routing table poisoning

✓ routers exchange data to build tables; attacker injects bad data



CDP

✓ Cisco Discovery Protocol; transmits in the clear; manipulation attack; disable this protocol



MAC flood

✓ An attack that sends numerous packets to the switch, each of which has a different source
MAC address, in an attempt to use up the memory on the switch and switch can
downgrade to hub



DHCP spoofing attack

✓ MitM attack listens for DHCP traffic then sends attacker IP address as default gateway



STP

✓ Spanning Tree Protocol. Protocol enabled on most switches that protects against switching
loops. A switching loop can be caused if two ports of a switch are connected together,
such as those caused when two ports of a switch are connected together.


|
✓ Thank You for Choosing Us! ✓ Resources & Updates: [Testtrackers - Stuvia US]
✓ © 2024 TestTrackers ✓ Your Success is Our Mission!
✓ Customer Support: [+254707240657]

Document information

Uploaded on
November 12, 2024
Number of pages
144
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$15.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ScholarsAscend
3.7
(82)
Sold
505
Followers
40
Items
30364
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions