AP® Cybersecurity Unit 3 flashcardsSecuring Networks
40 cards · about 10 minutes for the whole deck
Flashcard drill
Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.
- Position
- 1 / 40
- Due
- 40
- Mastered
- 0 / 40
This card: New
Flip the card before you rate it.
Address resolution protocol (ARP)
The protocol a default gateway uses to build a table pairing each device's IP address with its MAC address.
Topic 3.1: Network Vulnerabilities and Attacks
ARP poisoning
Sending fake ARP messages so the gateway links a victim's IP address to the attacker's MAC address. The victim's traffic then goes to the attacker.
Topic 3.1: Network Vulnerabilities and Attacks
MAC spoofing
Faking a MAC address so a device looks like a different, legitimate device on the network.
Topic 3.1: Network Vulnerabilities and Attacks
On-path (man-in-the-middle) attack
The attacker secretly sits between two parties, capturing and possibly changing their data, while both think they're talking directly.
Topic 3.1: Network Vulnerabilities and Attacks
MAC flooding
Sending a switch many frames with different MAC addresses until it starts broadcasting every frame, which lets the attacker eavesdrop.
Topic 3.1: Network Vulnerabilities and Attacks
Eavesdropping (sniffing)
Capturing data as it travels across a network so it can be recorded and copied.
Topic 3.1: Network Vulnerabilities and Attacks
DNS poisoning
Pretending to be an authoritative name server and planting a fake DNS record so a site's name leads to the attacker's fake site.
Topic 3.1: Network Vulnerabilities and Attacks
Credential harvesting
Setting up a fake login page that looks real so users type in their real usernames and passwords for the attacker to collect.
Topic 3.1: Network Vulnerabilities and Attacks
Smurf attack
A DoS attack: ICMP requests carrying the victim's address go to a network's broadcast address, and every device's reply floods the victim.
Topic 3.1: Network Vulnerabilities and Attacks
Denial of service (DoS)
An attack that makes a system or resource unavailable to its authorized users.
Topic 3.1: Network Vulnerabilities and Attacks
Distributed denial of service (DDoS)
A denial of service attack in which many devices attack the same target at the same time.
Topic 3.1: Network Vulnerabilities and Attacks
Rogue access point
An unauthorized wireless access point plugged into an open network port. It gives the attacker wireless access to the LAN, bypassing firewalls.
Topic 3.1: Network Vulnerabilities and Attacks
Vulnerability scanner
An automated tool that checks networks, devices and apps for known vulnerabilities and reports each one's severity and suggested fixes.
Topic 3.1: Network Vulnerabilities and Attacks
Router security policy
Minimum setup rules for routers, such as banning local user accounts, turning off unneeded services like Telnet and requiring a firewall.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Port security
A switch setting that limits how many MAC addresses can use one switch port. It blocks MAC flooding and strangers plugging into open jacks.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
MAC filtering
Letting only devices with approved MAC addresses join a network or use a switch port.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Split tunneling
Sending some of a device's traffic through the VPN and the rest straight to the internet at the same time. VPN policies often forbid it.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Extensible authentication protocol (EAP)
A way to make users sign in to a wireless network through an approved authentication server instead of a single shared password.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Beacon frame
A signal a wireless access point broadcasts with the network's SSID and encryption type. Turning beacons off makes the network harder to find.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
WPA3
The strongest wireless encryption protocol in the course framework (fall 2026). WEP, WPS and the original WPA have known flaws and are insecure.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Signal strength and direction
Wireless settings you can tune so an access point's signal covers only its intended space and doesn't leak outside.
Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security
Network segmentation
Dividing a network into smaller, isolated segments so an attack on one part can't easily spread, and each part can get its own security level.
Topic 3.3: Protecting Networks: Segmentation
Subnet
A segment of a network defined by a range of IP addresses. Subnets can contain a breach so fewer devices are exposed.
Topic 3.3: Protecting Networks: Segmentation
VLAN
A virtual LAN set up on switches. It logically separates devices even when they plug into the same physical switches.
Topic 3.3: Protecting Networks: Segmentation
Screened subnet (DMZ)
A lower-security segment between the internet and the internal network that holds public-facing servers, like a website.
Topic 3.3: Protecting Networks: Segmentation
Firewall
Software, on its own device or built into another such as a router, that allows or denies traffic into or out of a network or device.
Topic 3.4: Protecting Networks: Firewalls
Stateless firewall
A firewall that filters each packet by header details like IP addresses, ports and protocols, without tracking connections.
Topic 3.4: Protecting Networks: Firewalls
Stateful firewall
A firewall that also tracks the state of connections passing through it, so it can filter by connection, not just by packet. Also called dynamic packet filtering.
Topic 3.4: Protecting Networks: Firewalls
Next-generation firewall (NGFW)
A firewall that adds intrusion prevention, deep packet inspection and filtering by application to stateless and stateful filtering.
Topic 3.4: Protecting Networks: Firewalls
Access control list (ACL)
A firewall's ordered list of rules. Each rule names a direction, what to match (IP, port, service or app) and whether to allow or deny.
Topic 3.4: Protecting Networks: Firewalls
First-match rule
A firewall checks its rules in order and applies the first one that matches. Reordering rules can change what gets through.
Topic 3.4: Protecting Networks: Firewalls
Firewall placement
Put a firewall on each network segment and at every point where the internal network meets the internet.
Topic 3.4: Protecting Networks: Firewalls
Network intrusion detection system (NIDS)
An automated tool that analyzes network data for malicious activity and raises an alert. It doesn't block traffic itself.
Topic 3.5: Detecting Network Attacks
Network intrusion prevention system (NIPS)
Like a NIDS, but it can also stop an attack by closing ports, blocking IP or MAC addresses or rejecting protocols.
Topic 3.5: Detecting Network Attacks
SIEM
Security information and event management: collects and analyzes logs from many sources to spot attack patterns and alert analysts.
Topic 3.5: Detecting Network Attacks
Signature-based detection
Compares data with a database of known IoCs (signatures). Fast, cheap, almost no false positives, but it can't detect brand-new attacks.
Topic 3.5: Detecting Network Attacks
Anomaly-based detection
Compares activity with a baseline of normal traffic. It can catch new attacks but needs steady traffic, costs more and raises more false alarms.
Topic 3.5: Detecting Network Attacks
Hybrid detection
Uses both signature-based and anomaly-based detection. It's the most expensive option and makes the most alerts; it suits sensitive or critical networks.
Topic 3.5: Detecting Network Attacks
Alert fatigue
When responders see so many false positives that they start assuming every alert is false and take real ones less seriously.
Topic 3.5: Detecting Network Attacks
Indicator of compromise (IoC)
Evidence that an adversary has compromised a device or network, like connections to known malicious IPs, scans or traffic spikes.
Topic 3.5: Detecting Network Attacks