1
1

00:00:00,480  -->  00:00:03,070
<v ->Network hardening, in this section of the course,</v>
2

2

00:00:03,070  -->  00:00:05,460
we're going to talk all about network hardening.
3

3

00:00:05,460  -->  00:00:06,990
Now, as a network technician,
4

4

00:00:06,990  -->  00:00:08,530
part of your job is to help make sure
5

5

00:00:08,530  -->  00:00:11,770
our networks are secure by conducting network hardening.
6

6

00:00:11,770  -->  00:00:13,570
The term hardening in cybersecurity
7

7

00:00:13,570  -->  00:00:15,220
simply means to secure a system
8

8

00:00:15,220  -->  00:00:17,070
by reducing its attack surface
9

9

00:00:17,070  -->  00:00:19,110
or the surface of vulnerabilities.
10

10

00:00:19,110  -->  00:00:21,970
So, if you have a network with all of your ports open,
11

11

00:00:21,970  -->  00:00:23,790
you are really vulnerable.
12

12

00:00:23,790  -->  00:00:24,840
But on the other hand,
13

13

00:00:24,840  -->  00:00:26,370
if you have a network that blocks traffic
14

14

00:00:26,370  -->  00:00:29,050
on every single port going outbound or inbound,
15

15

00:00:29,050  -->  00:00:31,470
you have an isolated network that isn't very helpful
16

16

00:00:31,470  -->  00:00:33,110
or useful to your business.
17

17

00:00:33,110  -->  00:00:36,000
So for this reason, we have to find a healthy balance
18

18

00:00:36,000  -->  00:00:37,800
between operations and security.
19

19

00:00:37,800  -->  00:00:39,150
And the best way to do that,
20

20

00:00:39,150  -->  00:00:41,320
is by following a series of best practices
21

21

00:00:41,320  -->  00:00:43,030
in order to harden our network devices
22

22

00:00:43,030  -->  00:00:44,070
and our clients.
23

23

00:00:44,070  -->  00:00:47,180
So in this section, we're going to focus on just one domain
24

24

00:00:47,180  -->  00:00:48,530
and one objective.
25

25

00:00:48,530  -->  00:00:49,960
We'll be talking specifically about
26

26

00:00:49,960  -->  00:00:54,370
domain for network security and focusing on objective 4.3.
27

27

00:00:54,370  -->  00:00:56,870
Objective 4.3 states, given a scenario,
28

28

00:00:56,870  -->  00:00:59,300
you must apply network hardening techniques,
29

29

00:00:59,300  -->  00:01:02,150
which is why this section is called network hardening.
30

30

00:01:02,150  -->  00:01:04,250
Now, this includes a lot of best practices
31

31

00:01:04,250  -->  00:01:06,410
surrounding patch management for our clients,
32

32

00:01:06,410  -->  00:01:08,450
password security for all of our devices,
33

33

00:01:08,450  -->  00:01:10,190
shutting down unneeded services,
34

34

00:01:10,190  -->  00:01:11,330
increasing network security
35

35

00:01:11,330  -->  00:01:13,380
by using port security and VLANs,
36

36

00:01:13,380  -->  00:01:16,810
conducting inspections and policing, securing SNMP,
37

37

00:01:16,810  -->  00:01:19,160
utilizing access control lists properly,
38

38

00:01:19,160  -->  00:01:21,170
ensuring the security of our wireless devices,
39

39

00:01:21,170  -->  00:01:24,340
and even taking a look at some of our internet of things
40

40

00:01:24,340  -->  00:01:26,770
and the security considerations surrounding those.
41

41

00:01:26,770  -->  00:01:29,550
So, let's get started talking all about the different ways
42

42

00:01:29,550  -->  00:01:32,550
for us to harden our networks in this section of the course.
