1
00:00:06,570 --> 00:00:09,480
- Welcome to lesson 11, deep dive quiz.

2
00:00:09,480 --> 00:00:11,940
Now, lesson 11 was all
about given a scenario,

3
00:00:11,940 --> 00:00:14,880
apply security principles
to secure the enterprise.

4
00:00:14,880 --> 00:00:18,120
And we talked about a
wide range of topics here.

5
00:00:18,120 --> 00:00:19,920
We started with lesson 11.1,

6
00:00:19,920 --> 00:00:22,980
just understanding network
devices and how they operate.

7
00:00:22,980 --> 00:00:25,410
Then in 11.2, we did
network access control

8
00:00:25,410 --> 00:00:28,027
and looked at a whole
array of devices, IPSs

9
00:00:28,027 --> 00:00:32,550
and jump servers and proxy
servers and DLPs and NACs.

10
00:00:32,550 --> 00:00:35,760
In 11.3, we focused in
specifically on firewalls

11
00:00:35,760 --> 00:00:38,970
and different types and
generations of firewalls

12
00:00:38,970 --> 00:00:41,940
as well as how we configure
them, how we plan for them

13
00:00:41,940 --> 00:00:43,830
and looking at access control lists.

14
00:00:43,830 --> 00:00:47,040
And then in 11.4, we looked
at secure communications.

15
00:00:47,040 --> 00:00:51,287
We looked at SSL and TLS and IPSec VPNs

16
00:00:51,287 --> 00:00:54,510
and then just some
different ancillary overlays

17
00:00:54,510 --> 00:00:58,200
of how we could really secure
communications in our network,

18
00:00:58,200 --> 00:01:01,110
in our enterprise, and even
in our cloud environment.

19
00:01:01,110 --> 00:01:05,160
So that brings us to five
questions in this deep dive quiz.

20
00:01:05,160 --> 00:01:08,190
Great time to have a pen or
a pencil, piece of paper.

21
00:01:08,190 --> 00:01:10,140
Put me on pause as often as you need to.

22
00:01:10,140 --> 00:01:12,960
I really want you
answering these questions.

23
00:01:12,960 --> 00:01:14,370
And then when you're
ready, take me off pause

24
00:01:14,370 --> 00:01:16,440
and we'll go through the answers together.

25
00:01:16,440 --> 00:01:17,643
So let's get started.

26
00:01:19,260 --> 00:01:21,000
This tool is used to govern connections

27
00:01:21,000 --> 00:01:24,930
to the network based on pre
and post admission policies.

28
00:01:24,930 --> 00:01:29,930
Is this a NAC, an
IDS/IPS, a DLP or an EDR?

29
00:01:30,270 --> 00:01:34,470
Now you will see acronyms on
this exam, so be prepared.

30
00:01:34,470 --> 00:01:39,153
NAC, IDS/IPS, DLP or an EDR?

31
00:01:42,012 --> 00:01:43,312
What are you gonna choose?

32
00:01:44,250 --> 00:01:46,290
I'm gonna choose NAC which actually stands

33
00:01:46,290 --> 00:01:48,240
for network access control.

34
00:01:48,240 --> 00:01:50,970
Network Access control is what we use

35
00:01:50,970 --> 00:01:54,810
to govern connections
to the network, right?

36
00:01:54,810 --> 00:01:57,060
Based on those pre and
post admission policies,

37
00:01:57,060 --> 00:01:59,070
you go to connect your
device to the network.

38
00:01:59,070 --> 00:02:01,830
The NAC says, okay, I have
to evaluate your device.

39
00:02:01,830 --> 00:02:03,000
Not evaluating you, right?

40
00:02:03,000 --> 00:02:05,310
Evaluating your device for things like

41
00:02:05,310 --> 00:02:07,110
do you have the right antivirus?

42
00:02:07,110 --> 00:02:08,850
Are you patched and up to date?

43
00:02:08,850 --> 00:02:10,920
What operating system are you running?

44
00:02:10,920 --> 00:02:13,200
Do you have a local
firewall, you know, running?

45
00:02:13,200 --> 00:02:15,450
Whatever it is that are in the policies.

46
00:02:15,450 --> 00:02:17,400
And then based on that,
you're either allowed

47
00:02:17,400 --> 00:02:20,640
to continue in and the post
admission policies will apply

48
00:02:20,640 --> 00:02:23,160
or you're maybe sent
to a quarantine network

49
00:02:23,160 --> 00:02:25,200
or a remediation segment

50
00:02:25,200 --> 00:02:27,150
or just not even allowed on the network.

51
00:02:27,150 --> 00:02:28,793
So I'm going with NAC, do you like it?

52
00:02:28,793 --> 00:02:31,413
Yeah, let's double check and it's correct.

53
00:02:33,150 --> 00:02:35,910
All right, you receive a
vulnerability assessment report,

54
00:02:35,910 --> 00:02:38,490
and much to your surprise
and dismay, there appear

55
00:02:38,490 --> 00:02:41,790
to be several missing
critical security patches.

56
00:02:41,790 --> 00:02:44,610
Upon further investigation,
it was determined

57
00:02:44,610 --> 00:02:46,020
that the patches were installed

58
00:02:46,020 --> 00:02:48,420
as part of a cumulative update.

59
00:02:48,420 --> 00:02:51,540
How would you classify the
original report findings?

60
00:02:51,540 --> 00:02:54,480
A false positive, a false negative,

61
00:02:54,480 --> 00:02:58,260
a true negative or a true positive?

62
00:02:58,260 --> 00:03:00,060
So you get this report, you're like, wow,

63
00:03:00,060 --> 00:03:01,230
there's all these missing patches

64
00:03:01,230 --> 00:03:02,760
but then you investigate it.

65
00:03:02,760 --> 00:03:04,685
It's like, no, no, no, they're all there.

66
00:03:04,685 --> 00:03:06,390
They just, they were part
of a cumulative update.

67
00:03:06,390 --> 00:03:09,120
So the vulnerability scanner
didn't see it correctly.

68
00:03:09,120 --> 00:03:11,190
Just a false positive, false negative,

69
00:03:11,190 --> 00:03:13,803
true negative or true positive.

70
00:03:14,640 --> 00:03:16,140
Go ahead and make your choice.

71
00:03:18,000 --> 00:03:20,220
Well, this is going to
be a false positive.

72
00:03:20,220 --> 00:03:22,620
A false positive as in everything's okay

73
00:03:22,620 --> 00:03:24,870
but the system's coming
back and saying, nope,

74
00:03:24,870 --> 00:03:26,760
there's something wrong.

75
00:03:26,760 --> 00:03:28,980
It's aggravating, it's
time consuming, right?

76
00:03:28,980 --> 00:03:31,440
You have to like be chasing it
down to try to figure it out.

77
00:03:31,440 --> 00:03:32,640
And maybe there's even a little panic

78
00:03:32,640 --> 00:03:35,433
that sets in for a while,
but really everything's okay.

79
00:03:36,630 --> 00:03:39,030
A false negative is a
really dangerous state.

80
00:03:39,030 --> 00:03:41,730
A fault negative is when
there really is a problem

81
00:03:41,730 --> 00:03:43,440
but the system doesn't report it as such.

82
00:03:43,440 --> 00:03:45,690
It says, oh, everything's really fine.

83
00:03:45,690 --> 00:03:47,190
So that's really dangerous.

84
00:03:47,190 --> 00:03:50,280
A true negative is when
abnormal or unexpected

85
00:03:50,280 --> 00:03:53,130
events or activities are
correctly identified.

86
00:03:53,130 --> 00:03:56,040
A true positive is when your expected

87
00:03:56,040 --> 00:03:59,130
or normal activities or events
are correctly identified.

88
00:03:59,130 --> 00:04:01,320
So both true, negative and true positive,

89
00:04:01,320 --> 00:04:03,840
correctly identified, false negative

90
00:04:03,840 --> 00:04:06,390
and false positive are
incorrectly identified.

91
00:04:06,390 --> 00:04:09,600
And in this case, we're
looking at a false positive.

92
00:04:09,600 --> 00:04:11,100
Agree?

93
00:04:11,100 --> 00:04:13,401
Let's check and that's correct.

94
00:04:13,401 --> 00:04:16,200
All right, question three.

95
00:04:16,200 --> 00:04:21,200
The firewall rule Deny any
any any any should be where

96
00:04:21,870 --> 00:04:23,610
in the rule set sequence?

97
00:04:23,610 --> 00:04:28,610
At the end, before the allow
statements, at the beginning

98
00:04:28,710 --> 00:04:30,960
or it doesn't matter where.

99
00:04:30,960 --> 00:04:32,700
Okay, so what was the
really important thing

100
00:04:32,700 --> 00:04:36,150
I said you needed to remember
about a firewall rule?

101
00:04:36,150 --> 00:04:37,953
How are those rules processed?

102
00:04:40,740 --> 00:04:44,520
Well, they processed,
remember, from top to bottom.

103
00:04:44,520 --> 00:04:48,510
So as soon as it got to
that rule, deny any any any,

104
00:04:48,510 --> 00:04:51,180
right, at that point,
it's gonna deny any port,

105
00:04:51,180 --> 00:04:55,500
any protocol, any destination
IP and any source IP.

106
00:04:55,500 --> 00:04:57,525
So at the end's a good place for it.

107
00:04:57,525 --> 00:05:00,090
But if you put it before
the allow statements,

108
00:05:00,090 --> 00:05:02,220
all those allow statements
will be irrelevant.

109
00:05:02,220 --> 00:05:04,050
They'll never be read.

110
00:05:04,050 --> 00:05:05,790
If we put it the very beginning

111
00:05:05,790 --> 00:05:07,890
everything past that won't matter

112
00:05:07,890 --> 00:05:10,350
because we've already
said deny everything.

113
00:05:10,350 --> 00:05:13,410
All ports, all protocols,
all destination IPs,

114
00:05:13,410 --> 00:05:15,270
all source IPs.

115
00:05:15,270 --> 00:05:16,380
And doesn't matter where.

116
00:05:16,380 --> 00:05:18,630
Well, no, it really does
matter where, again,

117
00:05:18,630 --> 00:05:21,450
because once that rule is read,

118
00:05:21,450 --> 00:05:25,637
anything after that is gonna
be absolutely irrelevant.

119
00:05:25,637 --> 00:05:27,540
So we're gonna put it at the end.

120
00:05:27,540 --> 00:05:28,560
You like that?

121
00:05:28,560 --> 00:05:30,663
I'll double check and that's correct.

122
00:05:31,943 --> 00:05:34,110
All right, question four.

123
00:05:34,110 --> 00:05:38,220
I want you to identify the
two IPsec configuration modes.

124
00:05:38,220 --> 00:05:43,220
Tunnel mode, transmission
mode, transport mode, or TLS.

125
00:05:43,650 --> 00:05:44,880
I guess we're doing some alliteration

126
00:05:44,880 --> 00:05:45,780
here with Ts.

127
00:05:45,780 --> 00:05:49,230
Tunnel, transmission, transport or TLS.

128
00:05:49,230 --> 00:05:52,143
These are the two IP
set configuration modes.

129
00:05:53,520 --> 00:05:54,903
Okay, make that choice.

130
00:05:57,810 --> 00:06:00,270
I am gonna choose tunnel mode

131
00:06:00,270 --> 00:06:03,330
which is the default mode
where the entire packet

132
00:06:03,330 --> 00:06:06,580
is encapsulated in another
packet with a new header added

133
00:06:07,500 --> 00:06:10,410
and transport mode where
the payload is going to

134
00:06:10,410 --> 00:06:14,583
be encapsulated, but the
header is still exposed.

135
00:06:15,750 --> 00:06:18,600
Transmission mode is
really just a made up term

136
00:06:18,600 --> 00:06:20,760
and TLS isn't relevant here.

137
00:06:20,760 --> 00:06:22,560
So I'm going with tunnel and transport.

138
00:06:22,560 --> 00:06:23,880
How about you?

139
00:06:23,880 --> 00:06:27,000
Let's check and that is correct.

140
00:06:27,000 --> 00:06:28,450
All right, our last question.

141
00:06:29,430 --> 00:06:31,680
These are going to be true or false.

142
00:06:31,680 --> 00:06:33,780
So let's read all these questions first.

143
00:06:33,780 --> 00:06:37,050
SSL establishes a secure
channel by negotiation.

144
00:06:37,050 --> 00:06:38,490
True or false?

145
00:06:38,490 --> 00:06:42,240
In 2015, SSL version 3.0
was determined to be broken.

146
00:06:42,240 --> 00:06:43,860
True or false?

147
00:06:43,860 --> 00:06:46,950
TLS uses a well-known port 43.

148
00:06:46,950 --> 00:06:48,600
True or false?

149
00:06:48,600 --> 00:06:52,680
TLS establishes a secure
channel by negotiation.

150
00:06:52,680 --> 00:06:54,360
True or false?

151
00:06:54,360 --> 00:06:59,220
TLS 1.0 and 1.1 have officially
been declared deprecated.

152
00:06:59,220 --> 00:07:00,297
True or false?

153
00:07:00,297 --> 00:07:04,290
And TLS can be used to
secure browser-based VPNs.

154
00:07:04,290 --> 00:07:05,313
True or false?

155
00:07:06,210 --> 00:07:07,710
All right, great time to put me on pause

156
00:07:07,710 --> 00:07:09,420
and go through each of these and decide

157
00:07:09,420 --> 00:07:11,343
if they are true or false.

158
00:07:12,900 --> 00:07:14,430
All right, let's answer each one.

159
00:07:14,430 --> 00:07:18,167
SSL establishes a secure
channel by negotiation.

160
00:07:18,167 --> 00:07:20,250
That is true.

161
00:07:20,250 --> 00:07:23,862
In 2015, SSL 3.0 was
determined to be broken.

162
00:07:23,862 --> 00:07:25,830
That's gonna be false.

163
00:07:25,830 --> 00:07:27,000
It hasn't been broken.

164
00:07:27,000 --> 00:07:28,620
It has been what?

165
00:07:28,620 --> 00:07:33,270
Deprecated, so found to be
weak, not found to be broken.

166
00:07:33,270 --> 00:07:34,830
You shouldn't be using it

167
00:07:34,830 --> 00:07:38,550
but it has not been officially
designated as broken.

168
00:07:38,550 --> 00:07:41,940
It's still been being
designated as deprecated.

169
00:07:41,940 --> 00:07:44,677
TLS uses well known port 43.

170
00:07:44,677 --> 00:07:47,130
It's a lot about reading
for comprehension here.

171
00:07:47,130 --> 00:07:48,480
It's not 43.

172
00:07:48,480 --> 00:07:51,680
What port does both TLS and SSL use?

173
00:07:51,680 --> 00:07:53,103
443.

174
00:07:53,940 --> 00:07:55,533
So that's gonna be false.

175
00:07:56,520 --> 00:08:00,153
TLS establishes a secure
channel by negotiation.

176
00:08:02,280 --> 00:08:03,780
Is that true or false?

177
00:08:03,780 --> 00:08:05,730
No, that's gonna be false

178
00:08:05,730 --> 00:08:08,463
because it's by a cryptographic exchange.

179
00:08:09,660 --> 00:08:11,163
So there's false.

180
00:08:12,180 --> 00:08:15,480
TLS 1.0 and 1.1 have
officially been declared

181
00:08:15,480 --> 00:08:17,253
deprecated, true or false?

182
00:08:18,480 --> 00:08:19,593
That one is true.

183
00:08:20,580 --> 00:08:23,490
And TLS can be used to
secure browser-based VPNs,

184
00:08:23,490 --> 00:08:24,990
true or false?

185
00:08:24,990 --> 00:08:27,303
And that is also going to be true.

186
00:08:28,500 --> 00:08:31,770
So SSL establishes a secure
connection by negotiation.

187
00:08:31,770 --> 00:08:32,603
True.

188
00:08:32,603 --> 00:08:35,550
In 2015, SSL 3.0 was
determined to be broken?

189
00:08:35,550 --> 00:08:37,350
False because it's deprecated.

190
00:08:37,350 --> 00:08:39,450
TLS uses well-known port 43?

191
00:08:39,450 --> 00:08:41,610
False 'cause it's 443.

192
00:08:41,610 --> 00:08:44,820
TLS establishes secure
channel by negotiation.

193
00:08:44,820 --> 00:08:47,460
False 'cause they do a
cryptographic exchange.

194
00:08:47,460 --> 00:08:51,570
TLS 1.0 and 1.1 have officially
been declared deprecated.

195
00:08:51,570 --> 00:08:52,620
That is true.

196
00:08:52,620 --> 00:08:55,560
And TLS can be used to
secure browser-based VPNs

197
00:08:55,560 --> 00:08:56,763
and that is true.

198
00:08:57,630 --> 00:08:58,530
Let's double check.

199
00:08:58,530 --> 00:08:59,610
Do you agree?

200
00:08:59,610 --> 00:09:02,760
Let's see how we do and
those are all correct.

201
00:09:02,760 --> 00:09:03,780
Awesome.

202
00:09:03,780 --> 00:09:04,830
All right, congratulations.

203
00:09:04,830 --> 00:09:06,780
You did great again, I'm sure.

204
00:09:06,780 --> 00:09:09,390
I'm going through a lot
of information here,

205
00:09:09,390 --> 00:09:10,800
but stick with us.

206
00:09:10,800 --> 00:09:13,920
You know, we're not even quite
halfway through this course.

207
00:09:13,920 --> 00:09:16,050
We're at lesson 12, we have 29 lessons.

208
00:09:16,050 --> 00:09:17,760
Just keep on going.

209
00:09:17,760 --> 00:09:19,830
Lesson 12 is gonna be all about compare

210
00:09:19,830 --> 00:09:23,250
and contrast concepts and
strategies to protect data.

211
00:09:23,250 --> 00:09:24,200
I'll see you there.
