1
00:00:00,020 --> 00:00:01,320
In this section of the course,

2
00:00:01,320 --> 00:00:04,230
we're going to turn our attention to security infrastructure.

3
00:00:04,230 --> 00:00:06,000
Now, security infrastructure encompasses

4
00:00:06,000 --> 00:00:09,480
the hardware, software, networks, data, and policies

5
00:00:09,480 --> 00:00:11,100
that are working cohesively together

6
00:00:11,100 --> 00:00:13,890
to safeguard an organization's information and assets.

7
00:00:13,890 --> 00:00:15,930
Ensuring a robust and secure infrastructure

8
00:00:15,930 --> 00:00:18,210
is vital to thwart potential cyber threats,

9
00:00:18,210 --> 00:00:21,300
and to ensure the organization's data remains uncompromised.

10
00:00:21,300 --> 00:00:22,710
So, in this section,

11
00:00:22,710 --> 00:00:25,260
we're going to be focusing on Domains 3 and 4,

12
00:00:25,260 --> 00:00:28,890
and our coverage will include Objectives 3.2 and 4.5.

13
00:00:28,890 --> 00:00:31,500
Objective 3.2 states that given a scenario,

14
00:00:31,500 --> 00:00:33,540
you must be able to apply security principles

15
00:00:33,540 --> 00:00:35,550
to secure enterprise architecture.

16
00:00:35,550 --> 00:00:38,430
And Objective 4.5 states that given a scenario,

17
00:00:38,430 --> 00:00:40,800
you must be able to modify enterprise capabilities

18
00:00:40,800 --> 00:00:42,300
to enhance security.

19
00:00:42,300 --> 00:00:45,120
Now, first we're going to be covering ports and protocols.

20
00:00:45,120 --> 00:00:46,470
This lesson is going to be focused

21
00:00:46,470 --> 00:00:48,000
on providing you with a quick refresher

22
00:00:48,000 --> 00:00:50,430
on the ports and protocols you need to know for the exam.

23
00:00:50,430 --> 00:00:52,470
And this is mostly going to be a review for you

24
00:00:52,470 --> 00:00:53,400
if you've already completed

25
00:00:53,400 --> 00:00:56,070
your A+ or Network+ certifications.

26
00:00:56,070 --> 00:00:58,170
Next, we're going to cover firewalls.

27
00:00:58,170 --> 00:00:59,003
Now we're going to discuss

28
00:00:59,003 --> 00:01:00,540
the different types of firewalls available,

29
00:01:00,540 --> 00:01:02,430
including web application firewalls,

30
00:01:02,430 --> 00:01:04,019
unified threat management systems,

31
00:01:04,019 --> 00:01:05,880
and next-generation firewalls.

32
00:01:05,880 --> 00:01:06,900
We'll also look at the difference

33
00:01:06,900 --> 00:01:09,030
between a Layer 4 and Layer 7 firewall

34
00:01:09,030 --> 00:01:09,863
and how hardware

35
00:01:09,863 --> 00:01:12,090
and software firewalls work differently.

36
00:01:12,090 --> 00:01:14,970
Then we're going to take a look at configuring firewalls.

37
00:01:14,970 --> 00:01:17,010
Here, we're going to do a quick demonstration

38
00:01:17,010 --> 00:01:19,560
to show you how to set up rules and access control lists,

39
00:01:19,560 --> 00:01:21,090
how to select ports and protocols,

40
00:01:21,090 --> 00:01:23,220
and how to configure screen subnets.

41
00:01:23,220 --> 00:01:26,730
After that, we'll cover Intrusion Detection Systems, or IDS,

42
00:01:26,730 --> 00:01:29,490
and Intrusion Prevention Systems, known as IPS.

43
00:01:29,490 --> 00:01:30,780
By exploring what they are,

44
00:01:30,780 --> 00:01:32,460
how they're employed to identify threats,

45
00:01:32,460 --> 00:01:34,020
and showcasing their signatures,

46
00:01:34,020 --> 00:01:34,920
we're going to be able to provide you

47
00:01:34,920 --> 00:01:35,940
with a better understanding

48
00:01:35,940 --> 00:01:38,880
of their security techniques and mechanisms in place.

49
00:01:38,880 --> 00:01:41,280
Then, we'll discuss network appliances.

50
00:01:41,280 --> 00:01:43,650
Now, a network appliance is a specialized piece of hardware

51
00:01:43,650 --> 00:01:45,210
or software device that's designed

52
00:01:45,210 --> 00:01:47,820
to perform specific networking functions or services,

53
00:01:47,820 --> 00:01:50,580
such as load balancing, proxying, monitoring,

54
00:01:50,580 --> 00:01:53,490
or security enforcement within your computer network.

55
00:01:53,490 --> 00:01:55,920
After that, we'll explore port security.

56
00:01:55,920 --> 00:01:58,110
Now, port security is a network security feature

57
00:01:58,110 --> 00:02:00,240
that restricts and controls access to a network

58
00:02:00,240 --> 00:02:01,830
by allowing only authorized devices

59
00:02:01,830 --> 00:02:03,450
to connect to a specific physical

60
00:02:03,450 --> 00:02:05,550
or logical portion of that network

61
00:02:05,550 --> 00:02:08,520
based on its media access control, or MAC address,

62
00:02:08,520 --> 00:02:10,320
in order to prevent unauthorized access

63
00:02:10,320 --> 00:02:12,630
and potential security breaches from occurring.

64
00:02:12,630 --> 00:02:14,250
Now as we cover port security,

65
00:02:14,250 --> 00:02:17,730
we're going to be covering 802.1x and EAP as well.

66
00:02:17,730 --> 00:02:19,380
Next, we'll be exploring methods

67
00:02:19,380 --> 00:02:21,450
of securing network communications.

68
00:02:21,450 --> 00:02:22,283
This includes things,

69
00:02:22,283 --> 00:02:25,650
like virtual private networks, IPSec tunnels, TLS,

70
00:02:25,650 --> 00:02:27,810
and other ways to create secure backbones

71
00:02:27,810 --> 00:02:29,760
for all of our communication needs.

72
00:02:29,760 --> 00:02:31,140
Then we'll dive into the world

73
00:02:31,140 --> 00:02:34,500
of software-defined wide area networking, known as SD-WANs,

74
00:02:34,500 --> 00:02:38,370
and the Secure Access Service Edge, known as SASE.

75
00:02:38,370 --> 00:02:40,200
Now, SD-WANs are a technology

76
00:02:40,200 --> 00:02:42,510
that utilizes software-defined networking principles

77
00:02:42,510 --> 00:02:45,210
to manage and optimize a wide area network connection

78
00:02:45,210 --> 00:02:46,410
or WAN connection.

79
00:02:46,410 --> 00:02:48,540
And this allows us to enable our organizations

80
00:02:48,540 --> 00:02:49,590
to intelligently route

81
00:02:49,590 --> 00:02:51,120
and prioritize network traffic,

82
00:02:51,120 --> 00:02:52,470
improve their network performance,

83
00:02:52,470 --> 00:02:54,840
and enhance security by dynamically selecting

84
00:02:54,840 --> 00:02:56,820
the most efficient path for data transmission

85
00:02:56,820 --> 00:02:58,530
across multiple network links,

86
00:02:58,530 --> 00:03:01,860
including Broadband, Cellular, MPLS, and others,

87
00:03:01,860 --> 00:03:04,350
while offering centralized management and control.

88
00:03:04,350 --> 00:03:06,060
Now, SASE on the other hand,

89
00:03:06,060 --> 00:03:08,370
is a network security and connectivity framework

90
00:03:08,370 --> 00:03:09,660
that integrates network security

91
00:03:09,660 --> 00:03:12,570
and wide area networks into a cloud-based service

92
00:03:12,570 --> 00:03:14,610
that combines the elements of security services,

93
00:03:14,610 --> 00:03:17,460
like a firewall, secure web gateways, VPNs,

94
00:03:17,460 --> 00:03:19,440
and zero trust network access,

95
00:03:19,440 --> 00:03:22,320
altogether with SD-WAN capabilities.

96
00:03:22,320 --> 00:03:25,590
SASE is aiming to provide secure and scalable access

97
00:03:25,590 --> 00:03:26,520
to network resources

98
00:03:26,520 --> 00:03:28,980
for your users, devices and applications

99
00:03:28,980 --> 00:03:30,360
regardless of the location

100
00:03:30,360 --> 00:03:32,130
through a cloud-native architecture

101
00:03:32,130 --> 00:03:34,560
to simplify your network and security management

102
00:03:34,560 --> 00:03:37,110
while improving your performance and agility.

103
00:03:37,110 --> 00:03:38,580
After that, we're going to dive into

104
00:03:38,580 --> 00:03:40,290
some infrastructure considerations,

105
00:03:40,290 --> 00:03:41,700
including device placement,

106
00:03:41,700 --> 00:03:44,040
understanding security zones and screened subnets,

107
00:03:44,040 --> 00:03:45,690
comprehending attack surfaces,

108
00:03:45,690 --> 00:03:47,370
considering connectivity concerns,

109
00:03:47,370 --> 00:03:50,370
discussing device attributes, like active versus passive,

110
00:03:50,370 --> 00:03:52,410
or inline versus taps or monitors,

111
00:03:52,410 --> 00:03:53,730
and grasping failure modes,

112
00:03:53,730 --> 00:03:55,770
like fail-open and fail-closed

113
00:03:55,770 --> 00:03:57,780
within our security devices.

114
00:03:57,780 --> 00:03:59,040
Next, we're going to take a look

115
00:03:59,040 --> 00:04:01,290
at the selection of infrastructure controls.

116
00:04:01,290 --> 00:04:02,850
Here we're going to explore how to choose

117
00:04:02,850 --> 00:04:04,260
the right controls for your network

118
00:04:04,260 --> 00:04:06,900
to ensure your security architecture is not only robust,

119
00:04:06,900 --> 00:04:09,900
but also is tailored to your organization's unique needs.

120
00:04:09,900 --> 00:04:11,550
Finally, we're going to take a short quiz

121
00:04:11,550 --> 00:04:13,500
to see what you learned during this section of the course

122
00:04:13,500 --> 00:04:15,330
and review each of those quiz questions fully

123
00:04:15,330 --> 00:04:16,829
to ensure you can explain each answer

124
00:04:16,829 --> 00:04:18,510
and ensure why it was right.

125
00:04:18,510 --> 00:04:20,550
So if you're ready, let's begin our journey

126
00:04:20,550 --> 00:04:22,650
into the world of security infrastructure.

