CFS136 · Principles of Information Security

Chapter 9 Review: Securing Enterprise Infrastructure

A hands-on review station for security zones, zero trust, firewalls, intrusion detection, endpoint and deception technologies, email and application defenses, and operating system hardening from Chapter 9.

Start Here

Five review stations, each a different way to practice Chapter 9. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Design infrastructure security zones (DMZ, application tier, data tier, management tier, user segments) and explain how they limit attack propagation.
  • Explain the principles of zero trust architecture and apply them to access control decisions.
  • Tell apart firewall types (packet filtering, stateful, next-generation, web application) and the role of IDS and IPS in network defense.
  • Describe endpoint technologies (EDR, XDR, NAC, MDM), device hardening, and deception technologies (honeypots, honeytokens, canary accounts).
  • Match email and application defenses (SPF, DKIM, DMARC, input validation, parameterized queries, output encoding) to the threats they address.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/24Terms viewed
0/7Firewall answers correct
0/7Endpoint answers correct
0/7Defense answers correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.