1
00:00:06,580 --> 00:00:09,810
- Now in 11.4, we're going
to do our first lesson

2
00:00:09,810 --> 00:00:11,430
on secure communications.

3
00:00:11,430 --> 00:00:14,190
We're gonna revisit secure
communications again

4
00:00:14,190 --> 00:00:15,990
in a later lesson.

5
00:00:15,990 --> 00:00:18,420
A secure protocol is going to be a set

6
00:00:18,420 --> 00:00:20,910
of rules and procedures designed to ensure

7
00:00:20,910 --> 00:00:22,980
that we have secure
communication between two

8
00:00:22,980 --> 00:00:26,490
or more parties over a
network or the internet.

9
00:00:26,490 --> 00:00:28,800
Now the objective of secure communication

10
00:00:28,800 --> 00:00:31,842
or secure protocol is
either confidentiality,

11
00:00:31,842 --> 00:00:36,360
integrity, authentication, non-repudiation

12
00:00:36,360 --> 00:00:38,673
or really any combination of those.

13
00:00:40,170 --> 00:00:41,910
We're going to be talking specifically

14
00:00:41,910 --> 00:00:46,910
about two protocols in
this lesson, TLS and IPSec.

15
00:00:47,310 --> 00:00:49,800
TLS or Transport Layer Security

16
00:00:49,800 --> 00:00:53,190
and IPSec is Internet protocol security.

17
00:00:53,190 --> 00:00:56,474
And they both are widely used
to secure online transactions,

18
00:00:56,474 --> 00:01:00,933
email communication, and other
sensitive data transmissions.

19
00:01:01,952 --> 00:01:03,930
But before we talk about TLS

20
00:01:03,930 --> 00:01:05,400
we have to talk about SSL.

21
00:01:05,400 --> 00:01:07,620
And I know we've talked a
little bit about SSL already

22
00:01:07,620 --> 00:01:10,050
but I wanna talk some more about SSL.

23
00:01:10,050 --> 00:01:13,890
So SSL, Secure Socket
Layer, what's the history?

24
00:01:13,890 --> 00:01:17,280
Well, it was developed
back in 1995 by Netscape.

25
00:01:17,280 --> 00:01:20,100
SSL, Secure Socket Layer,
is used to establish

26
00:01:20,100 --> 00:01:22,110
a secure communication channel

27
00:01:22,110 --> 00:01:24,570
by negotiation using a stream cipher

28
00:01:24,570 --> 00:01:28,380
and SSL communicates on port 443.

29
00:01:28,380 --> 00:01:30,420
So basically the source would say

30
00:01:30,420 --> 00:01:33,210
to the destination, hey,
destination, I wanna talk to you.

31
00:01:33,210 --> 00:01:34,950
The destination says would say, cool

32
00:01:34,950 --> 00:01:37,140
but we need a secure channel.

33
00:01:37,140 --> 00:01:38,940
And the the source would say, okay,

34
00:01:38,940 --> 00:01:42,030
well let me tell you what I am capable of.

35
00:01:42,030 --> 00:01:45,360
And then based on negotiating that, right,

36
00:01:45,360 --> 00:01:46,590
the destination will say, okay,

37
00:01:46,590 --> 00:01:49,140
this is how we're going
to have a secure channel

38
00:01:49,140 --> 00:01:51,243
communicating on 443.

39
00:01:52,560 --> 00:01:54,390
So what's the current state?

40
00:01:54,390 --> 00:01:59,390
Well secure sock layer SSL
is insecure and outdated.

41
00:01:59,580 --> 00:02:04,230
In 2015, SSL 3.0 was deprecated,
meaning found to be weak

42
00:02:04,230 --> 00:02:07,410
by the internet engineering
task force, the IETF,

43
00:02:07,410 --> 00:02:09,450
due to numerous security vulnerabilities

44
00:02:09,450 --> 00:02:11,610
that have been discovered over the years

45
00:02:11,610 --> 00:02:14,910
and new vulnerabilities
continue to be discovered.

46
00:02:14,910 --> 00:02:18,060
So we don't wanna be using SSL anymore.

47
00:02:18,060 --> 00:02:21,570
Matter of fact, most browsers
no longer support SSL

48
00:02:21,570 --> 00:02:24,540
and we wanna make sure
that SSL previous versions

49
00:02:24,540 --> 00:02:27,810
like 2.0 and 3.0 are disabled, right?

50
00:02:27,810 --> 00:02:30,780
Because when they're enabled,
it makes the system vulnerable

51
00:02:30,780 --> 00:02:32,610
to an attack we've already discussed

52
00:02:32,610 --> 00:02:34,413
which is a downgrade attack.

53
00:02:35,520 --> 00:02:39,360
So what are we gonna use
instead if we're not using SSL?

54
00:02:39,360 --> 00:02:41,820
Well, that's where TLS comes in.

55
00:02:41,820 --> 00:02:45,750
Introduced in 1999, transport
layer security is used to

56
00:02:45,750 --> 00:02:48,090
establish a secure communication channel

57
00:02:48,090 --> 00:02:50,700
by using a cryptographic key exchange.

58
00:02:50,700 --> 00:02:51,660
And you're familiar with those.

59
00:02:51,660 --> 00:02:54,300
We've seen how cryptographic
key exchanges work.

60
00:02:54,300 --> 00:02:56,463
TLS communicates on port 443.

61
00:02:58,740 --> 00:03:02,318
Now one of the confusions
I think about TLS

62
00:03:02,318 --> 00:03:05,490
is that a lot of us
still, hopefully I don't,

63
00:03:05,490 --> 00:03:09,000
but a lot of us do still use the term SSL

64
00:03:09,000 --> 00:03:12,990
when we mean TLS because we've
been using SSL for so long

65
00:03:12,990 --> 00:03:16,890
that even though we've
already transitioned to TLS,

66
00:03:16,890 --> 00:03:19,260
people will still use the term SSL

67
00:03:19,260 --> 00:03:20,520
and it gets even a little more confusing

68
00:03:20,520 --> 00:03:21,720
'cause it runs on the same port.

69
00:03:21,720 --> 00:03:23,820
It runs on port 443.

70
00:03:23,820 --> 00:03:26,370
So if you're talking to
someone and they're talking

71
00:03:26,370 --> 00:03:28,435
about SSL, don't hesitate
to stop them and say

72
00:03:28,435 --> 00:03:31,264
do you mean SSL or TLS?

73
00:03:31,264 --> 00:03:32,370
You know, you won't sound wonky.

74
00:03:32,370 --> 00:03:34,830
You'll sound like you really
just trying to understand.

75
00:03:34,830 --> 00:03:37,350
So TLS is a successor and the recommended

76
00:03:37,350 --> 00:03:39,240
replacement for SSL.

77
00:03:39,240 --> 00:03:41,640
TLS is used to provide confidentiality,

78
00:03:41,640 --> 00:03:44,400
integrity and authenticity.

79
00:03:44,400 --> 00:03:47,460
Now, TLS uses a block encryption cipher

80
00:03:47,460 --> 00:03:49,860
and does include some
advanced security features

81
00:03:49,860 --> 00:03:51,720
and improved algorithms.

82
00:03:51,720 --> 00:03:54,210
Now the current version of TLS is 1.3

83
00:03:54,210 --> 00:03:55,890
and you always wanna be
using the current version.

84
00:03:55,890 --> 00:03:57,420
So as a new version comes out,

85
00:03:57,420 --> 00:03:59,040
you'll wanna move to a new version

86
00:03:59,040 --> 00:04:01,590
and the IETF has officially declared

87
00:04:01,590 --> 00:04:06,450
that both TLS 1.0 and
TLS 1.1 are deprecated,

88
00:04:06,450 --> 00:04:10,560
again meaning weak and vulnerable
and should not be used.

89
00:04:10,560 --> 00:04:13,260
So let's take a look at how
a TLS session actually works,

90
00:04:13,260 --> 00:04:14,523
how a connection is made.

91
00:04:15,579 --> 00:04:18,480
First, a client does a hello command

92
00:04:18,480 --> 00:04:21,300
and that's really the
secure connection requesting

93
00:04:21,300 --> 00:04:25,710
a TLS version, supported
ciphers and a random number.

94
00:04:25,710 --> 00:04:27,480
The server does a "hello",

95
00:04:27,480 --> 00:04:30,180
which is really a secure
connection response

96
00:04:30,180 --> 00:04:33,060
including TLS version,
selected cipher suite

97
00:04:33,060 --> 00:04:34,353
and a random number.

98
00:04:35,640 --> 00:04:37,740
Then we have a certificate exchange here.

99
00:04:37,740 --> 00:04:40,230
The server's going to send
its digital certificate

100
00:04:40,230 --> 00:04:42,960
which contains the server's public key

101
00:04:42,960 --> 00:04:45,873
and other trusted
information to the client.

102
00:04:47,119 --> 00:04:49,080
Then we have a server key exchange

103
00:04:49,080 --> 00:04:50,970
where the server's going
to send its public key.

104
00:04:50,970 --> 00:04:53,160
Remember, public keys
are freely distributed,

105
00:04:53,160 --> 00:04:55,530
to the client along
with information needed

106
00:04:55,530 --> 00:04:59,400
to establish a shared
secret or a symmetric key.

107
00:04:59,400 --> 00:05:01,290
Remember, symmetric key is
where you use the same key

108
00:05:01,290 --> 00:05:02,850
to encrypt and decrypt.

109
00:05:02,850 --> 00:05:04,200
Why are we using a symmetric key?

110
00:05:04,200 --> 00:05:06,150
Because it is computationally efficient

111
00:05:06,150 --> 00:05:08,133
and works well in large blocks of data.

112
00:05:09,480 --> 00:05:11,070
Then we'll have a client key exchange

113
00:05:11,070 --> 00:05:13,170
where the client
generates a symmetric key,

114
00:05:13,170 --> 00:05:15,180
encrypts it with the server's public key

115
00:05:15,180 --> 00:05:17,760
and sends it back to the server.

116
00:05:17,760 --> 00:05:19,770
Then we'll have our
cipher specification where

117
00:05:19,770 --> 00:05:21,570
both the client and the server switch

118
00:05:21,570 --> 00:05:25,020
to the agreed upon cipher
suite using that symmetric key.

119
00:05:25,020 --> 00:05:27,090
And then we have confirmation, the client

120
00:05:27,090 --> 00:05:29,670
and the server exchange messages to verify

121
00:05:29,670 --> 00:05:32,343
that a secure connection
has been established.

122
00:05:34,200 --> 00:05:36,600
Next step, we wanna talk about IP security

123
00:05:36,600 --> 00:05:40,590
or internet protocol security,
often referred to as IPSec

124
00:05:40,590 --> 00:05:43,980
which is a protocol
suite used to secure IP

125
00:05:43,980 --> 00:05:45,780
or internet protocol communications

126
00:05:45,780 --> 00:05:48,600
by providing authentication, integrity

127
00:05:48,600 --> 00:05:51,360
and confidentiality services.

128
00:05:51,360 --> 00:05:54,930
Now introduced in the mid
1990s, IPSec was originally

129
00:05:54,930 --> 00:05:57,420
designed to secure host
to host communication.

130
00:05:57,420 --> 00:06:01,260
Now, IPSec operates at the
network layer of the OSI model.

131
00:06:01,260 --> 00:06:03,480
That's layer three and can be used

132
00:06:03,480 --> 00:06:06,180
to encrypt data being sent to any system

133
00:06:06,180 --> 00:06:09,240
that can be identified by an IP address.

134
00:06:09,240 --> 00:06:12,420
Now IPSec can be implemented
in two modes, tunnel mode

135
00:06:12,420 --> 00:06:15,033
which is a default mode
and transport mode.

136
00:06:15,870 --> 00:06:18,540
Now, even though IPSec was
originally designed just

137
00:06:18,540 --> 00:06:21,390
to secure kind of host to
host communication, right,

138
00:06:21,390 --> 00:06:24,090
inside a a server room, at that point

139
00:06:24,090 --> 00:06:29,090
IPSec has now become the defacto
standard for IP-based VPNs.

140
00:06:31,260 --> 00:06:34,650
So looking at our two IPSec
modes, we have tunnel mode.

141
00:06:34,650 --> 00:06:37,950
In tunnel mode the entire
IP packet is encapsulated

142
00:06:37,950 --> 00:06:41,010
to become the payload of a new IP packet.

143
00:06:41,010 --> 00:06:44,070
And a new IP header is added on top

144
00:06:44,070 --> 00:06:46,020
of the original IP packet.

145
00:06:46,020 --> 00:06:48,240
So in tunnel mode, entire thing, right?

146
00:06:48,240 --> 00:06:50,940
The entire packet is gonna be encapsulated

147
00:06:50,940 --> 00:06:53,370
and it becomes the
payload of another packet.

148
00:06:53,370 --> 00:06:56,760
And that other packet
will have a new header.

149
00:06:56,760 --> 00:07:00,300
In transport mode, the
payload is encrypted,

150
00:07:00,300 --> 00:07:02,910
but not the IP header information.

151
00:07:02,910 --> 00:07:06,150
So we don't have to have a
packet on top of a packet.

152
00:07:06,150 --> 00:07:08,964
Transport mode has less overhead

153
00:07:08,964 --> 00:07:12,720
but could be considered less secure.

154
00:07:12,720 --> 00:07:15,390
So tunnel mode's gonna be
used for configurations

155
00:07:15,390 --> 00:07:17,100
that need a really secure connection

156
00:07:17,100 --> 00:07:18,963
between two different networks.

157
00:07:20,640 --> 00:07:23,340
So I just mentioned that
IPSec was a defacto standard

158
00:07:23,340 --> 00:07:26,370
for VPNs so let's talk about VPNs.

159
00:07:26,370 --> 00:07:29,160
VPNs is a virtual private network designed

160
00:07:29,160 --> 00:07:32,370
to facilitate secure
remote access communication

161
00:07:32,370 --> 00:07:33,780
over a public network.

162
00:07:33,780 --> 00:07:36,030
And what's the public
network we're talking about?

163
00:07:36,030 --> 00:07:38,280
Of course, over the internet.

164
00:07:38,280 --> 00:07:41,400
VPNs are an incredible
cost-effective alternative

165
00:07:41,400 --> 00:07:44,689
to dedicated point-to-point
connections like a T1

166
00:07:44,689 --> 00:07:48,150
or a T3 or an E1 or E3
which were very expensive

167
00:07:48,150 --> 00:07:50,130
and you'd have to go to the, you know,

168
00:07:50,130 --> 00:07:52,410
a phone company to get and
you might have to wait weeks

169
00:07:52,410 --> 00:07:54,720
or even months till it got installed.

170
00:07:54,720 --> 00:07:56,550
Now we can just use the circuitry

171
00:07:56,550 --> 00:07:58,500
of the internet for this communication.

172
00:07:59,550 --> 00:08:03,900
VPNs isolate network frames
from the surrounding networking

173
00:08:03,900 --> 00:08:07,230
by using a process known as
encapsulation or tunneling.

174
00:08:07,230 --> 00:08:09,660
Full tunneling requires
that all traffic is routed

175
00:08:09,660 --> 00:08:12,600
over the VPN and split
tunneling says some traffic

176
00:08:12,600 --> 00:08:13,890
can go over the VPN and some

177
00:08:13,890 --> 00:08:15,690
can directly access the internet.

178
00:08:15,690 --> 00:08:17,280
So imagine you're at home, you connect

179
00:08:17,280 --> 00:08:18,990
via your VPN to the office.

180
00:08:18,990 --> 00:08:20,700
Full tunneling means everything you do

181
00:08:20,700 --> 00:08:22,200
goes through that tunnel.

182
00:08:22,200 --> 00:08:23,880
Split tunneling would be okay,

183
00:08:23,880 --> 00:08:27,810
I am connected to the
office through my VPN

184
00:08:27,810 --> 00:08:29,190
but I can also go out directly

185
00:08:29,190 --> 00:08:32,070
to the internet without
going through that VPN.

186
00:08:32,070 --> 00:08:33,570
That would be split tunneling.

187
00:08:36,030 --> 00:08:39,450
Now, the two most used protocols
for virtual private network

188
00:08:39,450 --> 00:08:43,380
or VPN are gonna be are IPSec and TLS.

189
00:08:43,380 --> 00:08:47,400
Now IPSec VPNs are widely
used for site to site VPNs

190
00:08:47,400 --> 00:08:49,350
and remote access VPNs.

191
00:08:49,350 --> 00:08:52,900
Now because IPSec operates
at OSI layer three,

192
00:08:52,900 --> 00:08:57,690
IPSec VPNs can support
all IP-based applications.

193
00:08:57,690 --> 00:09:00,630
TLS VPNs are commonly used

194
00:09:00,630 --> 00:09:03,420
for remote access VPN configurations.

195
00:09:03,420 --> 00:09:07,167
Because TL operates at the
OSI layer seven, right,

196
00:09:07,167 --> 00:09:12,167
TLS VPNs generally only support
browser-based applications.

197
00:09:13,980 --> 00:09:17,820
I wanna just briefly introduce
you to two more concepts

198
00:09:17,820 --> 00:09:20,940
of ways that we can further
secure our networks.

199
00:09:20,940 --> 00:09:23,040
And the first is having software-defined

200
00:09:23,040 --> 00:09:25,770
wide area networks or SD-WANs.

201
00:09:25,770 --> 00:09:28,592
A software defined wide
area network is a technology

202
00:09:28,592 --> 00:09:31,320
that enables the creation
of a software-defined

203
00:09:31,320 --> 00:09:35,340
network overlay over an
existing wide area network.

204
00:09:35,340 --> 00:09:36,960
So why would we do that?

205
00:09:36,960 --> 00:09:38,430
Well, the SD-WAN focuses

206
00:09:38,430 --> 00:09:41,400
on providing software
defined application routing

207
00:09:41,400 --> 00:09:44,910
to the WAN but it includes
built-in security features

208
00:09:44,910 --> 00:09:49,200
such as encryption, firewalling,
and threat detection

209
00:09:49,200 --> 00:09:52,083
and response to improve the
security of the network.

210
00:09:54,270 --> 00:09:56,730
The other concept I want
you to become familiar with

211
00:09:56,730 --> 00:10:01,730
is known as Secure Access
Service Edge or SASE,

212
00:10:01,920 --> 00:10:04,170
which is a cloud-based
network security model

213
00:10:04,170 --> 00:10:06,360
that really combines wide area networking

214
00:10:06,360 --> 00:10:10,593
and security functions into
a single cloud-based service.

215
00:10:12,060 --> 00:10:14,730
Now, SASE is based on the
principle of software-defined

216
00:10:14,730 --> 00:10:18,090
networking and the SASE architecture

217
00:10:18,090 --> 00:10:20,100
integrates various security functions

218
00:10:20,100 --> 00:10:23,430
such as a secure web gateway,
a firewall-as-a-service,

219
00:10:23,430 --> 00:10:27,600
a secure access gateway, a
cloud access security broker

220
00:10:27,600 --> 00:10:29,820
and zero trust network access

221
00:10:29,820 --> 00:10:33,363
into a single unified
in the cloud platform.

222
00:10:35,160 --> 00:10:36,990
That was a lot of stuff, wasn't it?

223
00:10:36,990 --> 00:10:39,210
Yeah, let's do a three
second challenge together.

224
00:10:39,210 --> 00:10:41,400
Five challenge questions,
three seconds each.

225
00:10:41,400 --> 00:10:42,600
You ready?

226
00:10:42,600 --> 00:10:43,800
1, 2, 3.

227
00:10:43,800 --> 00:10:45,570
We're gonna start.

228
00:10:45,570 --> 00:10:48,390
This protocol is a successor to SSL.

229
00:10:48,390 --> 00:10:49,653
1, 2, 3.

230
00:10:51,840 --> 00:10:53,163
That's gonna be TLS.

231
00:10:54,150 --> 00:10:57,060
Number two, OSI layer three protocol suite

232
00:10:57,060 --> 00:10:59,490
that can be used to
encrypt data being sent

233
00:10:59,490 --> 00:11:03,633
between any systems
identified by an IP address.

234
00:11:05,010 --> 00:11:06,663
1, 2, 3.

235
00:11:07,590 --> 00:11:08,913
That's gonna be IPSec.

236
00:11:10,140 --> 00:11:12,450
Number three, in this IPSec mode

237
00:11:12,450 --> 00:11:15,420
the entire original IP
packet is encapsulated

238
00:11:15,420 --> 00:11:18,153
to become the payload of a new IP packet.

239
00:11:19,230 --> 00:11:20,883
1, 2, 3.

240
00:11:21,720 --> 00:11:23,043
It's gonna be tunnel mode.

241
00:11:24,000 --> 00:11:25,380
Number four.

242
00:11:25,380 --> 00:11:28,260
This VPN encapsulation
approach allows the routing

243
00:11:28,260 --> 00:11:31,560
of some traffic over the VPN
while letting other traffic

244
00:11:31,560 --> 00:11:33,423
directly access the internet.

245
00:11:34,410 --> 00:11:35,973
1, 2, 3.

246
00:11:37,110 --> 00:11:39,120
That's gonna be split tunneling.

247
00:11:39,120 --> 00:11:41,340
And lastly, number five.

248
00:11:41,340 --> 00:11:43,200
This cloud-based network security model

249
00:11:43,200 --> 00:11:45,150
combines wide area networking

250
00:11:45,150 --> 00:11:49,560
and security functions into
a single cloud-based service.

251
00:11:49,560 --> 00:11:51,183
1, 2, 3.

252
00:11:52,050 --> 00:11:56,610
That's gonna be secure
access service edge, SASE.

253
00:11:56,610 --> 00:11:58,083
Not an easy thing to say.

254
00:11:59,910 --> 00:12:02,250
All right, that takes us
to a security-in-action

255
00:12:02,250 --> 00:12:05,760
about secure communications
and VPN options.

256
00:12:05,760 --> 00:12:07,890
Your company is growing rapidly.

257
00:12:07,890 --> 00:12:10,290
Two remote offices are
planned, and employees

258
00:12:10,290 --> 00:12:13,710
in emerging markets are being
asked to work from home.

259
00:12:13,710 --> 00:12:16,800
They'll be connecting to
an on-premises data center

260
00:12:16,800 --> 00:12:19,440
and cost is a consideration.

261
00:12:19,440 --> 00:12:21,360
What is your best option for expanding

262
00:12:21,360 --> 00:12:22,860
your network securely?

263
00:12:22,860 --> 00:12:25,650
So we talked about different VPN options.

264
00:12:25,650 --> 00:12:28,170
Based on what we're
doing, two remote offices

265
00:12:28,170 --> 00:12:30,540
plus employees working from home,

266
00:12:30,540 --> 00:12:33,150
they're connecting to an
on-premise data center

267
00:12:33,150 --> 00:12:35,520
and cost is a consideration.

268
00:12:35,520 --> 00:12:37,080
So go ahead and put me on pause.

269
00:12:37,080 --> 00:12:38,940
Think about what your best options are

270
00:12:38,940 --> 00:12:40,863
for expanding your network security.

271
00:12:43,290 --> 00:12:44,790
Well, here's some of your options.

272
00:12:44,790 --> 00:12:46,710
For the remote office, we're going

273
00:12:46,710 --> 00:12:48,180
to have site to site, right?

274
00:12:48,180 --> 00:12:50,310
We're not doing individuals,
you know, host to host,

275
00:12:50,310 --> 00:12:51,690
we're doing site to site.

276
00:12:51,690 --> 00:12:53,340
So promptly our best bet is gonna be

277
00:12:53,340 --> 00:12:56,640
a site to site IPSec VPN, right?

278
00:12:56,640 --> 00:12:58,593
So remote office to corporate.

279
00:12:59,790 --> 00:13:01,530
Now for work at home users,

280
00:13:01,530 --> 00:13:03,870
it's gonna be important
to get an understanding of

281
00:13:03,870 --> 00:13:08,870
how often and with what
applications they need to connect.

282
00:13:09,030 --> 00:13:12,090
Because our options to
consider will be a TLS VPN

283
00:13:12,090 --> 00:13:17,090
which is browser based, or
a host to site IPSec VPN.

284
00:13:17,310 --> 00:13:19,020
So hard to know, we don't
have really have enough

285
00:13:19,020 --> 00:13:21,480
information to really
make a recommendation

286
00:13:21,480 --> 00:13:24,120
for our home users but we can explore both

287
00:13:24,120 --> 00:13:26,010
by saying what do we need to do?

288
00:13:26,010 --> 00:13:27,180
What are they gonna be doing?

289
00:13:27,180 --> 00:13:30,810
How often they can gonna connect,
through what applications?

290
00:13:30,810 --> 00:13:33,870
That'll help us kind of further refine

291
00:13:33,870 --> 00:13:35,770
what our recommendations are gonna be.

292
00:13:36,630 --> 00:13:37,890
Been able to do this?

293
00:13:37,890 --> 00:13:38,723
Absolutely.

294
00:13:38,723 --> 00:13:39,723
Security in action.

295
00:13:40,800 --> 00:13:42,360
All right, there's your word cloud.

296
00:13:42,360 --> 00:13:43,193
You know what to do.

297
00:13:43,193 --> 00:13:45,270
Do not move on until
you're really comfortable

298
00:13:45,270 --> 00:13:47,970
and confident with all of
these terms and concepts.

299
00:13:47,970 --> 00:13:50,160
And when you are, head on over

300
00:13:50,160 --> 00:13:52,260
to our lesson quiz and I'll see you there.
