Skip to main content

AP® Cybersecurity Unit 3 flashcardsSecuring Networks

40 cards · about 10 minutes for the whole deck

Flashcard drill

Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.

Position
1 / 40
Due
40
Mastered
0 / 40
Saved on this device · Sign in to sync

This card: New

Something wrong with this card?

What's wrong?

Please don't include personal details.

Flip the card before you rate it.

  • Address resolution protocol (ARP)

    The protocol a default gateway uses to build a table pairing each device's IP address with its MAC address.

    Topic 3.1: Network Vulnerabilities and Attacks

  • ARP poisoning

    Sending fake ARP messages so the gateway links a victim's IP address to the attacker's MAC address. The victim's traffic then goes to the attacker.

    Topic 3.1: Network Vulnerabilities and Attacks

  • MAC spoofing

    Faking a MAC address so a device looks like a different, legitimate device on the network.

    Topic 3.1: Network Vulnerabilities and Attacks

  • On-path (man-in-the-middle) attack

    The attacker secretly sits between two parties, capturing and possibly changing their data, while both think they're talking directly.

    Topic 3.1: Network Vulnerabilities and Attacks

  • MAC flooding

    Sending a switch many frames with different MAC addresses until it starts broadcasting every frame, which lets the attacker eavesdrop.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Eavesdropping (sniffing)

    Capturing data as it travels across a network so it can be recorded and copied.

    Topic 3.1: Network Vulnerabilities and Attacks

  • DNS poisoning

    Pretending to be an authoritative name server and planting a fake DNS record so a site's name leads to the attacker's fake site.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Credential harvesting

    Setting up a fake login page that looks real so users type in their real usernames and passwords for the attacker to collect.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Smurf attack

    A DoS attack: ICMP requests carrying the victim's address go to a network's broadcast address, and every device's reply floods the victim.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Denial of service (DoS)

    An attack that makes a system or resource unavailable to its authorized users.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Distributed denial of service (DDoS)

    A denial of service attack in which many devices attack the same target at the same time.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Rogue access point

    An unauthorized wireless access point plugged into an open network port. It gives the attacker wireless access to the LAN, bypassing firewalls.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Vulnerability scanner

    An automated tool that checks networks, devices and apps for known vulnerabilities and reports each one's severity and suggested fixes.

    Topic 3.1: Network Vulnerabilities and Attacks

  • Router security policy

    Minimum setup rules for routers, such as banning local user accounts, turning off unneeded services like Telnet and requiring a firewall.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Port security

    A switch setting that limits how many MAC addresses can use one switch port. It blocks MAC flooding and strangers plugging into open jacks.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • MAC filtering

    Letting only devices with approved MAC addresses join a network or use a switch port.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Split tunneling

    Sending some of a device's traffic through the VPN and the rest straight to the internet at the same time. VPN policies often forbid it.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Extensible authentication protocol (EAP)

    A way to make users sign in to a wireless network through an approved authentication server instead of a single shared password.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Beacon frame

    A signal a wireless access point broadcasts with the network's SSID and encryption type. Turning beacons off makes the network harder to find.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • WPA3

    The strongest wireless encryption protocol in the course framework (fall 2026). WEP, WPS and the original WPA have known flaws and are insecure.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Signal strength and direction

    Wireless settings you can tune so an access point's signal covers only its intended space and doesn't leak outside.

    Topic 3.2: Protecting Networks: Managerial Controls and Wireless Security

  • Network segmentation

    Dividing a network into smaller, isolated segments so an attack on one part can't easily spread, and each part can get its own security level.

    Topic 3.3: Protecting Networks: Segmentation

  • Subnet

    A segment of a network defined by a range of IP addresses. Subnets can contain a breach so fewer devices are exposed.

    Topic 3.3: Protecting Networks: Segmentation

  • VLAN

    A virtual LAN set up on switches. It logically separates devices even when they plug into the same physical switches.

    Topic 3.3: Protecting Networks: Segmentation

  • Screened subnet (DMZ)

    A lower-security segment between the internet and the internal network that holds public-facing servers, like a website.

    Topic 3.3: Protecting Networks: Segmentation

  • Firewall

    Software, on its own device or built into another such as a router, that allows or denies traffic into or out of a network or device.

    Topic 3.4: Protecting Networks: Firewalls

  • Stateless firewall

    A firewall that filters each packet by header details like IP addresses, ports and protocols, without tracking connections.

    Topic 3.4: Protecting Networks: Firewalls

  • Stateful firewall

    A firewall that also tracks the state of connections passing through it, so it can filter by connection, not just by packet. Also called dynamic packet filtering.

    Topic 3.4: Protecting Networks: Firewalls

  • Next-generation firewall (NGFW)

    A firewall that adds intrusion prevention, deep packet inspection and filtering by application to stateless and stateful filtering.

    Topic 3.4: Protecting Networks: Firewalls

  • Access control list (ACL)

    A firewall's ordered list of rules. Each rule names a direction, what to match (IP, port, service or app) and whether to allow or deny.

    Topic 3.4: Protecting Networks: Firewalls

  • First-match rule

    A firewall checks its rules in order and applies the first one that matches. Reordering rules can change what gets through.

    Topic 3.4: Protecting Networks: Firewalls

  • Firewall placement

    Put a firewall on each network segment and at every point where the internal network meets the internet.

    Topic 3.4: Protecting Networks: Firewalls

  • Network intrusion detection system (NIDS)

    An automated tool that analyzes network data for malicious activity and raises an alert. It doesn't block traffic itself.

    Topic 3.5: Detecting Network Attacks

  • Network intrusion prevention system (NIPS)

    Like a NIDS, but it can also stop an attack by closing ports, blocking IP or MAC addresses or rejecting protocols.

    Topic 3.5: Detecting Network Attacks

  • SIEM

    Security information and event management: collects and analyzes logs from many sources to spot attack patterns and alert analysts.

    Topic 3.5: Detecting Network Attacks

  • Signature-based detection

    Compares data with a database of known IoCs (signatures). Fast, cheap, almost no false positives, but it can't detect brand-new attacks.

    Topic 3.5: Detecting Network Attacks

  • Anomaly-based detection

    Compares activity with a baseline of normal traffic. It can catch new attacks but needs steady traffic, costs more and raises more false alarms.

    Topic 3.5: Detecting Network Attacks

  • Hybrid detection

    Uses both signature-based and anomaly-based detection. It's the most expensive option and makes the most alerts; it suits sensitive or critical networks.

    Topic 3.5: Detecting Network Attacks

  • Alert fatigue

    When responders see so many false positives that they start assuming every alert is false and take real ones less seriously.

    Topic 3.5: Detecting Network Attacks

  • Indicator of compromise (IoC)

    Evidence that an adversary has compromised a device or network, like connections to known malicious IPs, scans or traffic spikes.

    Topic 3.5: Detecting Network Attacks