1
00:00:00,000 --> 00:00:00,840
In this lesson,

2
00:00:00,840 --> 00:00:03,420
we're going to cover some infrastructure considerations.

3
00:00:03,420 --> 00:00:05,580
Now, our network infrastructure forms the backbone

4
00:00:05,580 --> 00:00:08,010
of all of our information technology environments

5
00:00:08,010 --> 00:00:10,320
and requires us to make a wide variety of decisions

6
00:00:10,320 --> 00:00:11,850
when we're designing the architecture

7
00:00:11,850 --> 00:00:14,400
that can potentially impact the efficiency, security,

8
00:00:14,400 --> 00:00:17,070
and resilience of our networks for years to come.

9
00:00:17,070 --> 00:00:19,290
These infrastructure considerations and decisions

10
00:00:19,290 --> 00:00:20,730
include things like the correct placement

11
00:00:20,730 --> 00:00:22,290
of your devices in the architecture,

12
00:00:22,290 --> 00:00:24,570
the use of security zones and screened subnets,

13
00:00:24,570 --> 00:00:26,130
understanding your attack surface,

14
00:00:26,130 --> 00:00:27,900
determining your connectivity methods,

15
00:00:27,900 --> 00:00:29,490
understanding your device attributes,

16
00:00:29,490 --> 00:00:31,440
and configuring the failure mode to utilize

17
00:00:31,440 --> 00:00:33,060
when things go wrong.

18
00:00:33,060 --> 00:00:35,700
Now first, let's consider the placement of your devices

19
00:00:35,700 --> 00:00:37,620
inside of your network architecture.

20
00:00:37,620 --> 00:00:38,970
The location of your devices,

21
00:00:38,970 --> 00:00:40,860
including things like your routers, your switches,

22
00:00:40,860 --> 00:00:43,380
and your access points can greatly influence

23
00:00:43,380 --> 00:00:46,410
both the performance and security of your entire network.

24
00:00:46,410 --> 00:00:48,870
The proper placement will ensure optimal data flow

25
00:00:48,870 --> 00:00:51,570
minimizes latency, and it provides a robust defense

26
00:00:51,570 --> 00:00:53,700
against potential security breaches.

27
00:00:53,700 --> 00:00:56,670
For example, by placing a router at the network's edge,

28
00:00:56,670 --> 00:00:57,930
you can help direct and filter

29
00:00:57,930 --> 00:01:00,810
incoming and outgoing traffic much more efficiently.

30
00:01:00,810 --> 00:01:03,210
Access points should also be strategically positioned

31
00:01:03,210 --> 00:01:05,430
to provide adequate coverage while attempting to keep

32
00:01:05,430 --> 00:01:08,460
all of your wireless signals located inside your facilities

33
00:01:08,460 --> 00:01:10,410
and to ensure interference between your system

34
00:01:10,410 --> 00:01:12,360
and others is being avoided.

35
00:01:12,360 --> 00:01:14,790
Switches on the other hand, are going to be designed to serve

36
00:01:14,790 --> 00:01:15,990
as the main connection point

37
00:01:15,990 --> 00:01:17,700
for most of your network devices,

38
00:01:17,700 --> 00:01:19,260
and so they need to be placed in a position

39
00:01:19,260 --> 00:01:21,960
that allows for your various devices to be easily connected

40
00:01:21,960 --> 00:01:24,750
to the proper physical segment of that network.

41
00:01:24,750 --> 00:01:26,850
If you place your devices in the wrong places,

42
00:01:26,850 --> 00:01:29,550
this can lead to network bottlenecks, vulnerability points,

43
00:01:29,550 --> 00:01:31,470
or even areas without connectivity.

44
00:01:31,470 --> 00:01:33,510
So it's really important that you carefully plan

45
00:01:33,510 --> 00:01:35,250
and evaluate your placement decisions

46
00:01:35,250 --> 00:01:37,500
while designing your network's architecture.

47
00:01:37,500 --> 00:01:39,030
Second, we need to consider

48
00:01:39,030 --> 00:01:40,710
how we're going to configure security zones

49
00:01:40,710 --> 00:01:43,350
and screened subnets in our network architecture.

50
00:01:43,350 --> 00:01:46,350
Now, a security zone is a distinct segment within a network,

51
00:01:46,350 --> 00:01:48,510
often created by logically isolating the segment

52
00:01:48,510 --> 00:01:51,360
using a firewall or other security device.

53
00:01:51,360 --> 00:01:53,760
These security zones or segments are going to be designed

54
00:01:53,760 --> 00:01:55,980
to contain devices with similar security requirements

55
00:01:55,980 --> 00:01:57,390
and levels of trust.

56
00:01:57,390 --> 00:01:59,730
For example, a company might have different zones

57
00:01:59,730 --> 00:02:02,880
for its public-facing services, internal employee resources,

58
00:02:02,880 --> 00:02:04,470
and sensitive data storage,

59
00:02:04,470 --> 00:02:05,880
and each of these will be configured

60
00:02:05,880 --> 00:02:07,290
with different access controls

61
00:02:07,290 --> 00:02:10,169
and different security policies based on the sensitivity

62
00:02:10,169 --> 00:02:11,700
or classification of the data

63
00:02:11,700 --> 00:02:13,890
contained in each of those security zones.

64
00:02:13,890 --> 00:02:15,780
Now, a screened subnet can also be created

65
00:02:15,780 --> 00:02:18,090
to act as a protective layer or buffer zone

66
00:02:18,090 --> 00:02:20,010
between an organization's internal network

67
00:02:20,010 --> 00:02:23,040
and an untrusted external network like the Internet.

68
00:02:23,040 --> 00:02:24,990
A screened subnet used to be referenced

69
00:02:24,990 --> 00:02:28,290
as something known as a DMZ or demilitarized zone,

70
00:02:28,290 --> 00:02:30,480
but in recent years, this term has been changed

71
00:02:30,480 --> 00:02:32,640
to a screened subnet instead.

72
00:02:32,640 --> 00:02:34,530
Note though, some network appliances

73
00:02:34,530 --> 00:02:36,750
and equipment that you might use on a daily basis

74
00:02:36,750 --> 00:02:39,720
may still use the term DMZ or demilitarized zone

75
00:02:39,720 --> 00:02:42,210
when you're configuring them, but for the exam,

76
00:02:42,210 --> 00:02:44,880
you should remember the term screened subnet instead

77
00:02:44,880 --> 00:02:47,280
because that's the term you're going to be asked about.

78
00:02:47,280 --> 00:02:48,960
Now, a screened subnet is used to host

79
00:02:48,960 --> 00:02:51,270
public-facing services like web servers,

80
00:02:51,270 --> 00:02:53,160
email servers, and DNS servers,

81
00:02:53,160 --> 00:02:55,020
while ensuring that if a security breach occurs

82
00:02:55,020 --> 00:02:56,640
inside of that screened subnet,

83
00:02:56,640 --> 00:02:58,740
the attacker will not have direct access

84
00:02:58,740 --> 00:03:00,120
to the core internal network

85
00:03:00,120 --> 00:03:02,940
that contains your most sensitive data or systems.

86
00:03:02,940 --> 00:03:04,620
This screened subnet is going to be used

87
00:03:04,620 --> 00:03:06,330
to provide an additional layer of security

88
00:03:06,330 --> 00:03:08,130
to make it harder for a malicious actor

89
00:03:08,130 --> 00:03:10,590
to reach the inner most and most valuable portions

90
00:03:10,590 --> 00:03:12,660
of your organization's network.

91
00:03:12,660 --> 00:03:14,910
Third, we need to consider the attack surface

92
00:03:14,910 --> 00:03:16,020
that our network architecture

93
00:03:16,020 --> 00:03:18,330
is going to represent to our organization.

94
00:03:18,330 --> 00:03:20,130
Now, the attack surface of a network

95
00:03:20,130 --> 00:03:22,560
refers to all the points where an unauthorized user

96
00:03:22,560 --> 00:03:23,940
can try and enter data to

97
00:03:23,940 --> 00:03:26,400
or extract data from an environment.

98
00:03:26,400 --> 00:03:27,690
In essence, it's the sum

99
00:03:27,690 --> 00:03:30,060
of all the potential vulnerabilities and risk points

100
00:03:30,060 --> 00:03:33,300
inside of a system, a network, or an application.

101
00:03:33,300 --> 00:03:35,430
As our networks grow and become more complex

102
00:03:35,430 --> 00:03:37,530
and we add additional devices, applications,

103
00:03:37,530 --> 00:03:39,870
and access points, the surface area

104
00:03:39,870 --> 00:03:42,090
and the attack surface will inevitably expand

105
00:03:42,090 --> 00:03:44,010
and become larger and larger.

106
00:03:44,010 --> 00:03:45,990
A larger attack surface generally equates

107
00:03:45,990 --> 00:03:47,310
to a higher level of risk

108
00:03:47,310 --> 00:03:49,470
because there are more opportunities for malicious actors

109
00:03:49,470 --> 00:03:52,320
to exploit weaknesses and vulnerabilities in your systems,

110
00:03:52,320 --> 00:03:54,240
including improper device placement,

111
00:03:54,240 --> 00:03:57,090
improperly configured devices, outdated software,

112
00:03:57,090 --> 00:04:00,000
unnecessary open ports, and weak access controls

113
00:04:00,000 --> 00:04:01,230
that are being used.

114
00:04:01,230 --> 00:04:03,480
To reduce your attack surface, you need to identify

115
00:04:03,480 --> 00:04:05,340
the vulnerabilities and either eliminate them

116
00:04:05,340 --> 00:04:07,590
or implement proper controls to mitigate the risk

117
00:04:07,590 --> 00:04:09,840
associated with those vulnerabilities.

118
00:04:09,840 --> 00:04:12,270
To safeguard our organization, it's really important

119
00:04:12,270 --> 00:04:13,920
that you regularly assess and minimize

120
00:04:13,920 --> 00:04:15,870
your organization's attack surface.

121
00:04:15,870 --> 00:04:17,519
By taking a proactive approach,

122
00:04:17,519 --> 00:04:18,930
you can ensure that you remain conscious

123
00:04:18,930 --> 00:04:20,160
of any potential threats

124
00:04:20,160 --> 00:04:21,750
and that you can act swiftly to address them

125
00:04:21,750 --> 00:04:23,940
in order to maintain the integrity and security

126
00:04:23,940 --> 00:04:25,950
of your organization's network.

127
00:04:25,950 --> 00:04:27,510
Now, fourth, we need to consider

128
00:04:27,510 --> 00:04:28,980
the different connectivity methods

129
00:04:28,980 --> 00:04:31,320
that are going to be used for our network architecture.

130
00:04:31,320 --> 00:04:33,390
Connectivity refers to how different components

131
00:04:33,390 --> 00:04:35,610
of a network are going to communicate with each other

132
00:04:35,610 --> 00:04:37,560
and with our external networks.

133
00:04:37,560 --> 00:04:39,330
The connectivity method that you choose

134
00:04:39,330 --> 00:04:40,800
will really influence the performance,

135
00:04:40,800 --> 00:04:44,310
reliability and security of your entire network or system.

136
00:04:44,310 --> 00:04:45,240
So if you're going to use

137
00:04:45,240 --> 00:04:48,090
a traditional wired network connection like ethernet,

138
00:04:48,090 --> 00:04:50,280
this is going to provide you with higher levels of stability

139
00:04:50,280 --> 00:04:53,220
and much faster speeds, but it is going to be more restrictive

140
00:04:53,220 --> 00:04:55,170
in terms of your end user's mobility

141
00:04:55,170 --> 00:04:56,670
than using a wireless network,

142
00:04:56,670 --> 00:04:58,950
and so it becomes much more difficult to move workstations

143
00:04:58,950 --> 00:05:00,900
and laptops to different offices

144
00:05:00,900 --> 00:05:03,270
because the wired cables will also have to be moved,

145
00:05:03,270 --> 00:05:05,220
or new ones will have to be installed

146
00:05:05,220 --> 00:05:07,470
to support your new office location.

147
00:05:07,470 --> 00:05:10,560
On the other hand, wireless connectivity methods like Wi-Fi,

148
00:05:10,560 --> 00:05:12,570
microwave links and satellite connections

149
00:05:12,570 --> 00:05:15,780
do offer us greater levels of flexibility and scalability

150
00:05:15,780 --> 00:05:18,000
because they're not limited to the preexisting wiring

151
00:05:18,000 --> 00:05:21,360
of a given network, but they do suffer from interference

152
00:05:21,360 --> 00:05:23,100
and potential security vulnerabilities

153
00:05:23,100 --> 00:05:25,920
if you don't properly configure your wireless devices.

154
00:05:25,920 --> 00:05:28,980
Furthermore, newer wired methods like fiber optics

155
00:05:28,980 --> 00:05:30,930
do provide higher speed data transmission

156
00:05:30,930 --> 00:05:33,840
over longer distances with minimal signal degradation

157
00:05:33,840 --> 00:05:36,510
than a microwave link or a satellite connection would.

158
00:05:36,510 --> 00:05:38,910
Sometimes to create a more robust connection,

159
00:05:38,910 --> 00:05:40,500
you might use a hybrid method

160
00:05:40,500 --> 00:05:42,420
that's going to combine various forms of connectivity

161
00:05:42,420 --> 00:05:44,760
to leverage the strengths of each different technology

162
00:05:44,760 --> 00:05:47,160
that's being used in order to ensure additional layers

163
00:05:47,160 --> 00:05:49,740
of redundancy are being put into your networks.

164
00:05:49,740 --> 00:05:51,270
Now, when you're designing or revising

165
00:05:51,270 --> 00:05:53,340
your network architecture, it's essential for you

166
00:05:53,340 --> 00:05:55,020
to weigh the benefits and drawbacks

167
00:05:55,020 --> 00:05:58,050
of each connectivity method based upon the specific needs

168
00:05:58,050 --> 00:06:00,540
and objectives of your organization's network.

169
00:06:00,540 --> 00:06:02,040
You should think about the various factors

170
00:06:02,040 --> 00:06:04,170
including scalability, speed requirements,

171
00:06:04,170 --> 00:06:06,780
security considerations, and budgetary constraints

172
00:06:06,780 --> 00:06:08,130
when you're determining the most suitable

173
00:06:08,130 --> 00:06:11,190
connectivity option for your organization to utilize.

174
00:06:11,190 --> 00:06:13,650
Fifth, we need to consider the device attributes

175
00:06:13,650 --> 00:06:15,660
that will affect how each device can be utilized

176
00:06:15,660 --> 00:06:17,340
in our network's architecture.

177
00:06:17,340 --> 00:06:19,320
When I refer to a device's attributes,

178
00:06:19,320 --> 00:06:21,120
I'm really referring to whether or not the device

179
00:06:21,120 --> 00:06:23,010
is considered to be active or passive,

180
00:06:23,010 --> 00:06:25,170
and if it's going to be placed in line or as a tap

181
00:06:25,170 --> 00:06:27,930
or monitor inside of your network architecture.

182
00:06:27,930 --> 00:06:30,810
Now, active devices like intrusion prevention systems

183
00:06:30,810 --> 00:06:32,940
are going to be used to monitor and act on suspicious

184
00:06:32,940 --> 00:06:35,760
or malicious network traffic by influencing data flows

185
00:06:35,760 --> 00:06:37,140
and making real-time decisions

186
00:06:37,140 --> 00:06:39,210
based on the network's current state.

187
00:06:39,210 --> 00:06:41,070
On the other hand, passive devices

188
00:06:41,070 --> 00:06:43,770
like an intrusion detection system will simply observe

189
00:06:43,770 --> 00:06:45,390
and report on the network traffic

190
00:06:45,390 --> 00:06:48,660
without actively intervening or altering its data flow.

191
00:06:48,660 --> 00:06:50,670
Network security devices can be installed

192
00:06:50,670 --> 00:06:54,240
as either an inline device or a tap-based configuration.

193
00:06:54,240 --> 00:06:56,040
Now an inline device is going to be positioned

194
00:06:56,040 --> 00:06:58,140
directly in the path of the network traffic

195
00:06:58,140 --> 00:06:59,730
and they have the capability to influence

196
00:06:59,730 --> 00:07:02,490
or block traffic as it passes through the device.

197
00:07:02,490 --> 00:07:05,220
This makes an inline device like a firewall, a router,

198
00:07:05,220 --> 00:07:07,890
or an intrusion prevention system, a really critical tool

199
00:07:07,890 --> 00:07:09,900
for tasks like filtering malicious traffic

200
00:07:09,900 --> 00:07:11,910
or optimizing our data flows.

201
00:07:11,910 --> 00:07:13,680
Taps and monitors, on the other hand,

202
00:07:13,680 --> 00:07:15,270
operate much more discreetly

203
00:07:15,270 --> 00:07:17,850
because they're placed outside of the direct network path

204
00:07:17,850 --> 00:07:19,110
and they're configured to only listen

205
00:07:19,110 --> 00:07:22,050
to the network's activity by capturing data for analysis

206
00:07:22,050 --> 00:07:24,450
without impacting the actual traffic.

207
00:07:24,450 --> 00:07:26,670
This makes them ideal for monitoring network health,

208
00:07:26,670 --> 00:07:28,740
performance and security without risking

209
00:07:28,740 --> 00:07:30,840
any kind of disruptions to your network.

210
00:07:30,840 --> 00:07:33,030
So, when you're selecting a security device

211
00:07:33,030 --> 00:07:34,860
to place in your network, you need to ensure

212
00:07:34,860 --> 00:07:36,390
that you consider whether it's going to be set up

213
00:07:36,390 --> 00:07:39,030
as an inline or tap device to best optimize

214
00:07:39,030 --> 00:07:41,190
your network security and performance.

215
00:07:41,190 --> 00:07:42,870
Always make sure to align your choices

216
00:07:42,870 --> 00:07:45,630
with the network's broader goals and challenges too.

217
00:07:45,630 --> 00:07:47,820
For example, an organization that requires

218
00:07:47,820 --> 00:07:50,370
real-time threat mitigation might prioritize

219
00:07:50,370 --> 00:07:52,440
installing an inline security appliance

220
00:07:52,440 --> 00:07:53,670
while a different organization

221
00:07:53,670 --> 00:07:56,580
who's focused more on monitoring might select a passive tap

222
00:07:56,580 --> 00:07:58,470
or monitor to use instead.

223
00:07:58,470 --> 00:08:00,510
Sixth, we need to consider the failure mode

224
00:08:00,510 --> 00:08:02,130
that we want to configure our devices to use

225
00:08:02,130 --> 00:08:03,840
in case something goes wrong.

226
00:08:03,840 --> 00:08:05,640
Now, the failure mode selected will determine

227
00:08:05,640 --> 00:08:07,290
how a device behaves when it encounters

228
00:08:07,290 --> 00:08:08,880
an error or malfunction.

229
00:08:08,880 --> 00:08:11,370
There are two primary failure modes that we can utilize,

230
00:08:11,370 --> 00:08:14,340
and these are known as fail-open or fail-closed.

231
00:08:14,340 --> 00:08:16,470
Now, when a device is set to fail-open,

232
00:08:16,470 --> 00:08:18,000
it's going to allow traffic to pass through

233
00:08:18,000 --> 00:08:19,890
without any inspection or filtering

234
00:08:19,890 --> 00:08:21,060
in the event of a failure

235
00:08:21,060 --> 00:08:22,440
to ensure that there is no disruption

236
00:08:22,440 --> 00:08:23,910
to the network service.

237
00:08:23,910 --> 00:08:25,680
If you're operating a firewall that's configured

238
00:08:25,680 --> 00:08:28,650
as a fail-open device, that firewall would simply allow

239
00:08:28,650 --> 00:08:31,530
all incoming and outgoing data to flow freely through it

240
00:08:31,530 --> 00:08:33,570
to maintain uninterrupted network connectivity

241
00:08:33,570 --> 00:08:34,980
if something goes wrong.

242
00:08:34,980 --> 00:08:37,049
But this firewall is no longer providing you

243
00:08:37,049 --> 00:08:39,120
with any kind of security when it's operating

244
00:08:39,120 --> 00:08:40,679
in this failed-open condition.

245
00:08:40,679 --> 00:08:42,690
So it's important to realize that too.

246
00:08:42,690 --> 00:08:45,180
Now, if you're using a device that's set to fail-closed,

247
00:08:45,180 --> 00:08:46,350
it's going to do the opposite

248
00:08:46,350 --> 00:08:49,110
and it's going to block all traffic in the event of a failure

249
00:08:49,110 --> 00:08:51,960
to ensure that your security of your network remains intact.

250
00:08:51,960 --> 00:08:53,700
If you're operating a firewall that's configured

251
00:08:53,700 --> 00:08:55,170
as a fail-closed device,

252
00:08:55,170 --> 00:08:57,210
if a malfunction occurs in your firewall,

253
00:08:57,210 --> 00:08:58,860
that firewall is going to start blocking

254
00:08:58,860 --> 00:09:01,770
all incoming and all outgoing data in order to maintain

255
00:09:01,770 --> 00:09:03,840
the security of your data and your network.

256
00:09:03,840 --> 00:09:06,510
But this will fully interrupt your network connectivity

257
00:09:06,510 --> 00:09:08,970
and prevent any normal firewall operations to occur

258
00:09:08,970 --> 00:09:10,740
during this failed state.

259
00:09:10,740 --> 00:09:12,750
Now, your choice between using a failed-open

260
00:09:12,750 --> 00:09:14,910
or failed-close mode is really going to depend

261
00:09:14,910 --> 00:09:16,770
on the organization's security policy

262
00:09:16,770 --> 00:09:18,540
and the criticality of the network segment

263
00:09:18,540 --> 00:09:20,580
that device is trying to protect.

264
00:09:20,580 --> 00:09:22,830
For example, a data center that's used to store

265
00:09:22,830 --> 00:09:25,320
all the organization's sensitive financial data

266
00:09:25,320 --> 00:09:27,330
might opt to use a failed-closed mode

267
00:09:27,330 --> 00:09:28,710
to maintain the security of the data

268
00:09:28,710 --> 00:09:30,540
in the case of a device failure.

269
00:09:30,540 --> 00:09:32,010
On the other hand, if you're operating

270
00:09:32,010 --> 00:09:34,350
a guest wireless network, you might prefer to use

271
00:09:34,350 --> 00:09:36,930
a failed-open mode to ensure uninterrupted access

272
00:09:36,930 --> 00:09:38,130
for all of your users,

273
00:09:38,130 --> 00:09:39,510
because you're not really trying to protect

274
00:09:39,510 --> 00:09:41,010
any sensitive data or servers

275
00:09:41,010 --> 00:09:43,620
inside of that guest wireless network anyway.

276
00:09:43,620 --> 00:09:45,840
So remember, infrastructure considerations

277
00:09:45,840 --> 00:09:48,300
play a pivotal role in the efficiency and security

278
00:09:48,300 --> 00:09:49,800
of a network environment.

279
00:09:49,800 --> 00:09:52,200
Therefore, it's important to consider the device placement

280
00:09:52,200 --> 00:09:54,330
in your network architecture so you can optimize

281
00:09:54,330 --> 00:09:56,160
your data flow and security.

282
00:09:56,160 --> 00:09:58,710
Security zones and screened subnets can also be used

283
00:09:58,710 --> 00:10:00,630
to help isolate and protect network segments

284
00:10:00,630 --> 00:10:02,310
inside of your architecture.

285
00:10:02,310 --> 00:10:05,100
As a cybersecurity professional, it is our job to understand

286
00:10:05,100 --> 00:10:06,810
our organization's attack surface

287
00:10:06,810 --> 00:10:09,300
and provide ways to minimize it so that our security

288
00:10:09,300 --> 00:10:10,860
is going to be increased.

289
00:10:10,860 --> 00:10:12,300
Additionally, you need to consider

290
00:10:12,300 --> 00:10:14,280
the various connectivity methods that you can use

291
00:10:14,280 --> 00:10:16,590
in your networks so that you can choose the right one

292
00:10:16,590 --> 00:10:18,810
to provide both the performance and flexibility

293
00:10:18,810 --> 00:10:20,850
that your organization needs.

294
00:10:20,850 --> 00:10:23,160
As you install various network and security appliances

295
00:10:23,160 --> 00:10:25,410
in your architecture, you also need to consider

296
00:10:25,410 --> 00:10:28,110
whether they should be placed in an active or passive role,

297
00:10:28,110 --> 00:10:29,070
and if they're going to be installed

298
00:10:29,070 --> 00:10:32,520
as either inline or as a tap or monitor position.

299
00:10:32,520 --> 00:10:34,740
Finally, you should be aware that the failure mode

300
00:10:34,740 --> 00:10:37,260
of your various devices includes things like fail-open

301
00:10:37,260 --> 00:10:39,660
and fail-closed, and you need to know what they're going to do

302
00:10:39,660 --> 00:10:42,210
and what protections they will or will not provide to you

303
00:10:42,210 --> 00:10:43,680
if the device becomes overloaded

304
00:10:43,680 --> 00:10:45,570
or fails to operate as designed.

305
00:10:45,570 --> 00:10:47,940
By considering all these infrastructure considerations,

306
00:10:47,940 --> 00:10:50,190
you can build a more secure network architecture

307
00:10:50,190 --> 00:10:52,080
and that the security of your organizational network

308
00:10:52,080 --> 00:10:53,133
remains intact.

