1
00:00:06,510 --> 00:00:07,380
- In this lesson,

2
00:00:07,380 --> 00:00:09,810
we're gonna focus in on zero trust,

3
00:00:09,810 --> 00:00:13,833
which is an emerging but
extraordinarily important topic.

4
00:00:15,450 --> 00:00:18,510
Zero trust, you'll sometimes
see abbreviated as ZT,

5
00:00:18,510 --> 00:00:20,130
is a security framework

6
00:00:20,130 --> 00:00:23,130
that requires all subjects, all assets,

7
00:00:23,130 --> 00:00:27,120
and all workflows to be
authenticated, authorized,

8
00:00:27,120 --> 00:00:28,590
and here's the key,

9
00:00:28,590 --> 00:00:31,980
continuously validated
before being granted

10
00:00:31,980 --> 00:00:35,100
or keeping access to
applications and data.

11
00:00:35,100 --> 00:00:36,450
Think about what we do now, right?

12
00:00:36,450 --> 00:00:38,880
We assign permissions, and
those are the permissions,

13
00:00:38,880 --> 00:00:40,230
the rights and permissions you have.

14
00:00:40,230 --> 00:00:41,520
And if you have privilege,

15
00:00:41,520 --> 00:00:44,400
like you're an admin, domain
admin, enterprise admin,

16
00:00:44,400 --> 00:00:48,690
root user, superuser in the
Unix or Linux world, right,

17
00:00:48,690 --> 00:00:51,210
you have those privileges,

18
00:00:51,210 --> 00:00:53,430
those rights and permissions all the time.

19
00:00:53,430 --> 00:00:54,547
Here we're saying,

20
00:00:54,547 --> 00:00:56,940
"Uh-uh, that's not what
we're gonna do," right?

21
00:00:56,940 --> 00:01:00,180
That everything has to be
authenticated, authorized,

22
00:01:00,180 --> 00:01:02,310
and continuously validated

23
00:01:02,310 --> 00:01:06,240
before granting or keeping
access to applications and data.

24
00:01:06,240 --> 00:01:10,380
So it is an entirely,
entirely different way, right,

25
00:01:10,380 --> 00:01:13,143
of looking at trust in an environment.

26
00:01:14,340 --> 00:01:16,800
Now the goal is to prevent
unauthorized access

27
00:01:16,800 --> 00:01:18,450
to data and services

28
00:01:18,450 --> 00:01:21,480
coupled with making
access control enforcement

29
00:01:21,480 --> 00:01:24,333
absolutely as granular as possible.

30
00:01:26,490 --> 00:01:29,160
So when we think about
a zero trust network

31
00:01:29,160 --> 00:01:31,200
or the view of a zero trust network,

32
00:01:31,200 --> 00:01:34,410
these are the assumptions
that we're basing it off on.

33
00:01:34,410 --> 00:01:38,730
No implicit zone trust,
no ownership assumptions,

34
00:01:38,730 --> 00:01:41,490
the fact that our
connections will be insecure,

35
00:01:41,490 --> 00:01:44,673
and that we wanna have a
consistent security policy.

36
00:01:46,500 --> 00:01:48,660
So no implicit zone trust means

37
00:01:48,660 --> 00:01:52,320
that the entire enterprise
private network is

38
00:01:52,320 --> 00:01:55,380
not to be considered
an implicit trust zone.

39
00:01:55,380 --> 00:01:58,050
Now, that's again another way
of thinking things, right?

40
00:01:58,050 --> 00:02:00,030
We've always thought
about our internal network

41
00:02:00,030 --> 00:02:01,770
as the trusted network.

42
00:02:01,770 --> 00:02:02,857
Here we're saying,

43
00:02:02,857 --> 00:02:04,740
"Nope, even though it's our enterprise,

44
00:02:04,740 --> 00:02:06,660
even though it's our private network,

45
00:02:06,660 --> 00:02:10,170
we're not gonna consider
it an implicit trust zone."

46
00:02:10,170 --> 00:02:12,960
That assets should always act

47
00:02:12,960 --> 00:02:16,380
as if an attacker is present
on the enterprise network.

48
00:02:16,380 --> 00:02:18,360
So we should always make an assumption

49
00:02:18,360 --> 00:02:20,400
that even on our private network,

50
00:02:20,400 --> 00:02:21,573
there is an attacker.

51
00:02:22,410 --> 00:02:24,840
The second is no ownership assumptions.

52
00:02:24,840 --> 00:02:26,400
And that's the assumption

53
00:02:26,400 --> 00:02:30,030
that devices that are on our
network may or may not be owned

54
00:02:30,030 --> 00:02:32,310
or configurable by the enterprise.

55
00:02:32,310 --> 00:02:35,220
So you could well have
devices in your environment

56
00:02:35,220 --> 00:02:37,020
maybe that are personally owned by a user,

57
00:02:37,020 --> 00:02:38,340
maybe their cell phone,

58
00:02:38,340 --> 00:02:40,770
or perhaps by a vendor,

59
00:02:40,770 --> 00:02:43,050
and that not all of your resources,

60
00:02:43,050 --> 00:02:45,180
the enterprise-owned resources are

61
00:02:45,180 --> 00:02:47,130
in an enterprise-owned infrastructure.

62
00:02:47,130 --> 00:02:50,250
Maybe they're your devices
that are in, you know,

63
00:02:50,250 --> 00:02:51,960
other networks, or other environments,

64
00:02:51,960 --> 00:02:54,060
or mobile, or at someone's home.

65
00:02:54,060 --> 00:02:57,120
So no ownership assumptions
that, you know, that you own it,

66
00:02:57,120 --> 00:02:58,530
that you're configuring it, right,

67
00:02:58,530 --> 00:03:00,483
that you've got complete control.

68
00:03:01,470 --> 00:03:03,570
The third is insecure connections.

69
00:03:03,570 --> 00:03:07,020
And that's a remote subject
should assume that local,

70
00:03:07,020 --> 00:03:09,900
meaning a non-enterprise-owned network,

71
00:03:09,900 --> 00:03:11,460
is a hostile network.

72
00:03:11,460 --> 00:03:13,650
So we're gonna assume that, you know,

73
00:03:13,650 --> 00:03:15,090
all our other networks are hostile,

74
00:03:15,090 --> 00:03:16,830
that our connections are hostile.

75
00:03:16,830 --> 00:03:19,710
And we're gonna assume that
all traffic is being monitored

76
00:03:19,710 --> 00:03:22,230
and potentially modified.

77
00:03:22,230 --> 00:03:24,090
It's kind of a depressing view, right,

78
00:03:24,090 --> 00:03:25,350
because we're saying,

79
00:03:25,350 --> 00:03:27,660
assume you're always
being attacked, right?

80
00:03:27,660 --> 00:03:28,710
Don't make any assumptions

81
00:03:28,710 --> 00:03:30,720
about ownership and configuration.

82
00:03:30,720 --> 00:03:34,410
And assume that your
connections are all insecure.

83
00:03:34,410 --> 00:03:36,270
And then the last part is

84
00:03:36,270 --> 00:03:38,850
that we should have a
consistent security policy.

85
00:03:38,850 --> 00:03:42,600
So assets and workloads should
retain their security posture

86
00:03:42,600 --> 00:03:45,930
when moving to or from an
enterprise-owned infrastructure.

87
00:03:45,930 --> 00:03:47,910
So our security posture shouldn't change

88
00:03:47,910 --> 00:03:50,370
depending upon location.

89
00:03:50,370 --> 00:03:54,000
So no implicit zone trust,
no ownership assumptions,

90
00:03:54,000 --> 00:03:56,100
fact that our connections
should all be assumed

91
00:03:56,100 --> 00:03:57,270
to be insecure,

92
00:03:57,270 --> 00:04:01,023
and that we wanna really have
a consistent security policy.

93
00:04:02,760 --> 00:04:05,490
Now the core principles of zero trust are

94
00:04:05,490 --> 00:04:08,010
actually really-well
detailed and discussed

95
00:04:08,010 --> 00:04:10,350
in another NIST special publication.

96
00:04:10,350 --> 00:04:13,200
NIST being National Institute
of Standards and Technology,

97
00:04:13,200 --> 00:04:16,380
this is Special Publication 800-207,

98
00:04:16,380 --> 00:04:19,320
really one of the best documents
I've seen on zero trust.

99
00:04:19,320 --> 00:04:22,080
And they talk about four core principles:

100
00:04:22,080 --> 00:04:25,710
continuous verification,
access limitation,

101
00:04:25,710 --> 00:04:27,750
we're gonna limit the blast radius,

102
00:04:27,750 --> 00:04:29,580
think of it as a bomb going off,

103
00:04:29,580 --> 00:04:31,113
and we want to automate.

104
00:04:32,850 --> 00:04:34,470
Continuous verification says

105
00:04:34,470 --> 00:04:36,240
we're always, always, always,

106
00:04:36,240 --> 00:04:39,810
always, always, always
going to verify access

107
00:04:39,810 --> 00:04:42,300
all the time for all resources.

108
00:04:42,300 --> 00:04:44,050
That's our continuous verification.

109
00:04:45,060 --> 00:04:48,330
Our access limitation
principle will say access

110
00:04:48,330 --> 00:04:51,870
to individual enterprise
resources is going to be granted

111
00:04:51,870 --> 00:04:54,240
on a per-session basis.

112
00:04:54,240 --> 00:04:57,150
So just because you had
access yesterday doesn't mean

113
00:04:57,150 --> 00:04:58,863
you're gonna have access tomorrow.

114
00:05:00,120 --> 00:05:01,740
Limit the blast radius

115
00:05:01,740 --> 00:05:04,500
so that we wanna be able
to minimize the impact

116
00:05:04,500 --> 00:05:07,380
if the internal or external
resources are breached.

117
00:05:07,380 --> 00:05:08,820
Now, we might do that with segmentation.

118
00:05:08,820 --> 00:05:10,500
We might do that with
having least privilege,

119
00:05:10,500 --> 00:05:12,360
meaning that we're signing the
least rights and permissions

120
00:05:12,360 --> 00:05:14,370
necessary to do a job,

121
00:05:14,370 --> 00:05:15,750
but we wanna make sure

122
00:05:15,750 --> 00:05:18,840
that if internal or external
resources are breached, right,

123
00:05:18,840 --> 00:05:20,220
the impact is small.

124
00:05:20,220 --> 00:05:22,560
We wanna limit the blast radius.

125
00:05:22,560 --> 00:05:25,650
And lastly that we can't do this manually.

126
00:05:25,650 --> 00:05:27,630
If we're going to implement zero trust,

127
00:05:27,630 --> 00:05:31,020
we really, really have to
have automated processes.

128
00:05:31,020 --> 00:05:34,380
So we have to automate content
collection and response,

129
00:05:34,380 --> 00:05:37,140
whether that's in credential
management or in workloads,

130
00:05:37,140 --> 00:05:41,130
or how we configure and manage
and provision our endpoints

131
00:05:41,130 --> 00:05:43,230
or our SIEMs,

132
00:05:43,230 --> 00:05:45,690
as well as the intake and processing

133
00:05:45,690 --> 00:05:46,800
of our threat intelligence.

134
00:05:46,800 --> 00:05:48,600
We'll be talking a lot
more about automation

135
00:05:48,600 --> 00:05:50,763
at different points later in this course.

136
00:05:53,550 --> 00:05:56,790
So let's talk from a
conceptual or high-level view,

137
00:05:56,790 --> 00:05:59,730
how do we actually implement
a zero-trust environment?

138
00:05:59,730 --> 00:06:00,690
And to do that,

139
00:06:00,690 --> 00:06:03,240
we need to talk about
control and data planes.

140
00:06:03,240 --> 00:06:04,297
And you might be thinking,

141
00:06:04,297 --> 00:06:06,300
"A plane? What's a plane?"

142
00:06:06,300 --> 00:06:07,320
Well, in networking,

143
00:06:07,320 --> 00:06:09,630
a plane is this abstract concept

144
00:06:09,630 --> 00:06:12,030
of where certain processes take place.

145
00:06:12,030 --> 00:06:14,040
And in a zero-trust environment,

146
00:06:14,040 --> 00:06:15,750
there needs to be a separation,

147
00:06:15,750 --> 00:06:19,590
also known as the control
plane, and the data plane.

148
00:06:19,590 --> 00:06:22,710
Now the control plane is used
by infrastructure components

149
00:06:22,710 --> 00:06:25,050
to maintain and configure assets,

150
00:06:25,050 --> 00:06:28,200
access control, and
communication security.

151
00:06:28,200 --> 00:06:29,970
In a zero-trust environment,

152
00:06:29,970 --> 00:06:31,920
requests for access are gonna be made

153
00:06:31,920 --> 00:06:33,630
through the control plane.

154
00:06:33,630 --> 00:06:36,900
And then a data plane is
used for communication

155
00:06:36,900 --> 00:06:40,143
or moving data between
software components.

156
00:06:41,730 --> 00:06:43,980
So going back to SP 207,

157
00:06:43,980 --> 00:06:46,800
the NIST publication on
zero trust architecture,

158
00:06:46,800 --> 00:06:49,020
let me share with you this visual

159
00:06:49,020 --> 00:06:50,820
of what the architecture looks like.

160
00:06:50,820 --> 00:06:53,130
Above the dotted line, we
have the control plane.

161
00:06:53,130 --> 00:06:55,740
Below the dotted line,
we have the data plane.

162
00:06:55,740 --> 00:06:56,910
Up in the control plane,

163
00:06:56,910 --> 00:06:58,980
this is where we have a
policy decision point.

164
00:06:58,980 --> 00:07:00,180
There's two components there:

165
00:07:00,180 --> 00:07:02,460
a policy engine and a
policy administrator.

166
00:07:02,460 --> 00:07:04,020
And below the line,

167
00:07:04,020 --> 00:07:06,570
this is where we actually have
our assets in the data plane

168
00:07:06,570 --> 00:07:09,300
and where these systems
are going to communicate

169
00:07:09,300 --> 00:07:10,200
with each other.

170
00:07:10,200 --> 00:07:12,240
So we start with our subject,

171
00:07:12,240 --> 00:07:13,770
trying to access a system,

172
00:07:13,770 --> 00:07:16,080
but they're untrusted
to begin with, right?

173
00:07:16,080 --> 00:07:16,980
So they're on a system.

174
00:07:16,980 --> 00:07:19,020
They've asked for some access.

175
00:07:19,020 --> 00:07:20,160
They're untrusted.

176
00:07:20,160 --> 00:07:23,430
They stop and hit this
policy enforcement point.

177
00:07:23,430 --> 00:07:25,680
We now come up to the control plane,

178
00:07:25,680 --> 00:07:27,780
up to our policy decision point

179
00:07:27,780 --> 00:07:29,010
where our policy engine

180
00:07:29,010 --> 00:07:31,530
and then our policy
administrator will make

181
00:07:31,530 --> 00:07:35,310
the stop, go, yes, no,
yay, nay decision, right?

182
00:07:35,310 --> 00:07:37,980
If it is trusted, that
information comes back down,

183
00:07:37,980 --> 00:07:39,480
and now they have been trusted,

184
00:07:39,480 --> 00:07:41,880
and they can access that
enterprise resource.

185
00:07:41,880 --> 00:07:46,880
And that's gonna happen every
single time they try to access

186
00:07:47,100 --> 00:07:48,800
that enterprise resource.

187
00:07:48,800 --> 00:07:51,120
So we have a control plane
making all those decisions.

188
00:07:51,120 --> 00:07:52,500
We have the data plane,

189
00:07:52,500 --> 00:07:55,290
who becomes the recipient or
the beneficiary, if you will,

190
00:07:55,290 --> 00:07:57,210
of those decisions.

191
00:07:57,210 --> 00:07:59,130
So let's talk a little bit
more about what do we mean,

192
00:07:59,130 --> 00:08:00,150
what's a policy engine?

193
00:08:00,150 --> 00:08:01,380
What's a policy administrator?

194
00:08:01,380 --> 00:08:02,790
What's a policy decision point,

195
00:08:02,790 --> 00:08:05,040
or a policy enforcement point?

196
00:08:05,040 --> 00:08:06,360
And as we're going through this,

197
00:08:06,360 --> 00:08:09,063
keep drawing in mind as
I'm defining them to you.

198
00:08:10,260 --> 00:08:13,740
The policy decision point
focuses really as the gatekeeper,

199
00:08:13,740 --> 00:08:15,840
and it has two logical components.

200
00:08:15,840 --> 00:08:19,800
It has the policy engine and
the policy administrator.

201
00:08:19,800 --> 00:08:21,960
Now the policy engine, or the PE,

202
00:08:21,960 --> 00:08:24,000
is responsible for the ultimate decision

203
00:08:24,000 --> 00:08:27,693
to grant access to a
resource for a given subject.

204
00:08:29,100 --> 00:08:30,240
The policy administrator,

205
00:08:30,240 --> 00:08:31,890
remember that's the second part

206
00:08:31,890 --> 00:08:33,600
of the policy decision point.

207
00:08:33,600 --> 00:08:34,860
We had two components.

208
00:08:34,860 --> 00:08:37,140
The policy administrator, or the PA,

209
00:08:37,140 --> 00:08:41,250
generates any necessary
session-specific authentication

210
00:08:41,250 --> 00:08:43,170
and authentication token,

211
00:08:43,170 --> 00:08:47,400
or credential used to access
the enterprise resource.

212
00:08:47,400 --> 00:08:49,080
And then when we come down below the line,

213
00:08:49,080 --> 00:08:51,480
that's where we have our
policy enforcement point.

214
00:08:51,480 --> 00:08:54,750
And the PEP is responsible
for enabling, monitoring,

215
00:08:54,750 --> 00:08:56,940
and eventually terminating the connections

216
00:08:56,940 --> 00:09:00,330
between a subject and
an enterprise resource.

217
00:09:00,330 --> 00:09:01,920
Now this is a really big topic.

218
00:09:01,920 --> 00:09:03,930
And there's a lot of pieces here.

219
00:09:03,930 --> 00:09:05,940
I like that the NIST document.

220
00:09:05,940 --> 00:09:08,910
I think it's really helpful
for studying a little bit more.

221
00:09:08,910 --> 00:09:12,120
You will not have to have
really an in-depth understanding

222
00:09:12,120 --> 00:09:12,953
for the exam,

223
00:09:12,953 --> 00:09:14,970
but you do need to understand this

224
00:09:14,970 --> 00:09:17,700
from a fundamental concept
or principle perspective.

225
00:09:17,700 --> 00:09:19,200
And later on when we're talking

226
00:09:19,200 --> 00:09:21,270
about access control and authentication,

227
00:09:21,270 --> 00:09:24,273
we're gonna revisit a lot of
these zero-trust concepts.

228
00:09:25,560 --> 00:09:27,960
So that, my friends, brings us
to a three-second challenge,

229
00:09:27,960 --> 00:09:29,850
five challenge questions,
three seconds each.

230
00:09:29,850 --> 00:09:31,950
I know you know how to do this now.

231
00:09:31,950 --> 00:09:33,003
Ready? Let's do it.

232
00:09:34,230 --> 00:09:36,930
The premise that trust is
never granted implicitly

233
00:09:36,930 --> 00:09:39,633
but must be continually evaluated.

234
00:09:40,500 --> 00:09:43,290
One, two, three.

235
00:09:43,290 --> 00:09:45,300
Oh, everybody's gonna get this one right?

236
00:09:45,300 --> 00:09:46,860
Let's do it.

237
00:09:46,860 --> 00:09:48,483
ZT, or zero trust.

238
00:09:51,330 --> 00:09:54,600
Used in ZTA, that's
zero trust architecture,

239
00:09:54,600 --> 00:09:56,370
by infrastructure components

240
00:09:56,370 --> 00:10:00,300
to maintain and configure
assets, access control,

241
00:10:00,300 --> 00:10:02,433
and communication security.

242
00:10:03,270 --> 00:10:05,850
Going back to which component it was.

243
00:10:05,850 --> 00:10:08,700
One, two, three.

244
00:10:08,700 --> 00:10:10,600
And that's gonna be the control plane.

245
00:10:12,960 --> 00:10:16,530
Used in ZTA for communications
between software components.

246
00:10:16,530 --> 00:10:18,690
Well, if it's not the
control plane, it must be?

247
00:10:18,690 --> 00:10:21,060
One, two, three.

248
00:10:21,060 --> 00:10:22,173
That's the data plane.

249
00:10:24,540 --> 00:10:27,120
The ZTA logical component responsible

250
00:10:27,120 --> 00:10:31,080
for the ultimate decision to
grant access to a resource

251
00:10:31,080 --> 00:10:32,673
for a given subject.

252
00:10:33,990 --> 00:10:35,883
One, two, three.

253
00:10:36,870 --> 00:10:39,243
It's gonna be the policy
engine, or the PE.

254
00:10:40,170 --> 00:10:42,180
I know for many of you, this is all new.

255
00:10:42,180 --> 00:10:45,360
So you may have to go back
through it more than once.

256
00:10:45,360 --> 00:10:48,930
And lastly, the ZTA logical
component responsible

257
00:10:48,930 --> 00:10:50,610
for enabling, monitoring,

258
00:10:50,610 --> 00:10:52,860
and eventually terminating connections

259
00:10:52,860 --> 00:10:56,043
between a subject and
an enterprise resource.

260
00:10:57,210 --> 00:10:59,043
One, two, three.

261
00:10:59,910 --> 00:11:02,673
That's gonna be our PEP, our
policy enforcement point.

262
00:11:04,230 --> 00:11:06,210
All right, so let's do a
security and action case study

263
00:11:06,210 --> 00:11:07,230
about zero trust.

264
00:11:07,230 --> 00:11:09,150
I'm gonna give you a zero trust scenario.

265
00:11:09,150 --> 00:11:10,350
I'm gonna ask you a question.

266
00:11:10,350 --> 00:11:12,510
After we get that far, good
place to put me on pause,

267
00:11:12,510 --> 00:11:13,380
write down your answer,

268
00:11:13,380 --> 00:11:15,840
and then we'll do the response together.

269
00:11:15,840 --> 00:11:18,900
Your organization contracts
with a number of third parties

270
00:11:18,900 --> 00:11:21,120
for building environmental
control monitoring

271
00:11:21,120 --> 00:11:24,420
and maintenance, for example,
smart lighting and HVAC,

272
00:11:24,420 --> 00:11:26,160
across your enterprise.

273
00:11:26,160 --> 00:11:27,510
Now, to provide service,

274
00:11:27,510 --> 00:11:30,780
contractors need network
connectivity to their devices

275
00:11:30,780 --> 00:11:32,250
and to the Internet.

276
00:11:32,250 --> 00:11:34,230
And your boss wants to know,

277
00:11:34,230 --> 00:11:36,360
maybe your boss has
been reading up on this,

278
00:11:36,360 --> 00:11:39,030
wants to know if it makes
sense to implement ZT,

279
00:11:39,030 --> 00:11:42,120
or zero trust, in this scenario.

280
00:11:42,120 --> 00:11:43,590
What would you say?

281
00:11:43,590 --> 00:11:45,030
So think about that for a moment.

282
00:11:45,030 --> 00:11:47,490
Put me on pause, jot down some notes,

283
00:11:47,490 --> 00:11:49,390
and then we'll do a response together.

284
00:11:52,470 --> 00:11:53,760
Absolutely, right?

285
00:11:53,760 --> 00:11:55,800
Zero trust could allow service providers

286
00:11:55,800 --> 00:11:58,650
time-sensitive access to their systems

287
00:11:58,650 --> 00:12:00,450
and access to the Internet

288
00:12:00,450 --> 00:12:02,910
while obscuring enterprise resources.

289
00:12:02,910 --> 00:12:05,790
So only get access to what
they need when they need it

290
00:12:05,790 --> 00:12:07,410
for a limited amount of time,

291
00:12:07,410 --> 00:12:10,563
when they have been
continuously re-evaluated.

292
00:12:12,060 --> 00:12:13,800
In a zero-trust environment,

293
00:12:13,800 --> 00:12:15,540
each user, each device,

294
00:12:15,540 --> 00:12:19,020
and the application can have
its own perimeter security.

295
00:12:19,020 --> 00:12:20,850
Access permissions are controlled

296
00:12:20,850 --> 00:12:23,460
with individuals having just-enough

297
00:12:23,460 --> 00:12:27,810
or sometimes referred to
as just-in-time access.

298
00:12:27,810 --> 00:12:29,550
Later on, one of our lessons,

299
00:12:29,550 --> 00:12:31,380
we're gonna be talking about JIT,

300
00:12:31,380 --> 00:12:35,160
or just-in-time privilege
access management.

301
00:12:35,160 --> 00:12:37,020
But being able to understand

302
00:12:37,020 --> 00:12:39,180
how zero trust would
work in your environment

303
00:12:39,180 --> 00:12:41,370
and what its application is,

304
00:12:41,370 --> 00:12:43,920
that, my friends, is
definitely security in action.

305
00:12:45,510 --> 00:12:46,800
There's your word cloud.

306
00:12:46,800 --> 00:12:48,720
There's not a lot here,

307
00:12:48,720 --> 00:12:52,140
but probably a lot of really
unfamiliar components,

308
00:12:52,140 --> 00:12:54,660
whether we're talking
about the control plane,

309
00:12:54,660 --> 00:12:57,360
or the data plane, or the
policy enforcement point.

310
00:12:57,360 --> 00:12:58,800
Probably a lot of new stuff here.

311
00:12:58,800 --> 00:13:00,240
So please make sure, right,

312
00:13:00,240 --> 00:13:03,180
that you can speak to
everything on this word cloud

313
00:13:03,180 --> 00:13:04,830
before you move on.

314
00:13:04,830 --> 00:13:07,463
And when you're ready, I'll
see you in the next lesson.
