CFS136 · Principles of Information Security

Chapter 11 Review: Secure Network Design

A hands-on review station for secure and insecure protocols, VPNs, wireless security, network access control, DNS security, and network segmentation from Chapter 11.

Start Here

Five review stations, each a different way to practice Chapter 11. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Tell apart secure and insecure protocols, know their ports, and explain why deprecated protocols like Telnet, FTP, and HTTP put a network at risk.
  • Explain how a VPN builds an encrypted tunnel over an untrusted network, and compare site-to-site and remote access designs along with the risk of split tunneling.
  • Describe wireless security with WPA2, WPA3, enterprise and personal modes, EAP types, and attacks such as rogue access points and evil twins.
  • Explain network access control with 802.1X, and compare agent-based and agentless approaches.
  • Evaluate DNS security controls and apply segmentation and micro-segmentation to limit lateral movement.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/18Terms viewed
0/9Protocol answers correct
0/8Design concepts correct
0/10Wireless and NAC correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.