Skip to main content

AP® Cybersecurity

Not weighted by unit

Unit 3: Securing Networks

Data is always moving between devices, and every network connection is a chance for an attacker to listen in, pose as another device or flood a system. You'll learn common network attacks, how to set up wireless security, why splitting a network into segments limits damage, and how to write firewall rules. You'll also read network logs and choose detection tools to spot attacks.

Study this unit

Flashcards (40)Practice questions (61)Cybersecurity must-know sheet

Free-response questions on this unit

Write your own answer, then score it with the rubric or with AI.

Big ideas

  • Attackers on a network can eavesdrop, impersonate devices or knock services offline
  • Strong wireless settings and switch policies keep strangers off the network
  • Segmentation keeps a breach inside one part of the network
  • Firewalls check rules in order, and the first matching rule wins
  • Every detection method trades off speed, cost and false alarms

Full unit reviews

Longer videos that cover the whole unit. Good for a first pass or a final review.

  • CS50 Cybersecurity - Lecture 2 - Securing Systems

    CS50Watch on YouTube (opens in a new tab)

  • Cybersecurity Architecture: Networks

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • Cybersecurity Assets, Network Threats & Vulnerabilities | Google Cybersecurity Certificate

    Grow with GoogleWatch on YouTube (opens in a new tab)

In ARP poisoning, an attacker fakes address-table entries so a victim's traffic flows to them, an on-path (man-in-the-middle) attack. MAC flooding overloads a switch so it broadcasts everything, letting the attacker eavesdrop, and DNS poisoning plants fake records that send users to a fake login site. A smurf attack floods a victim with ICMP replies, a denial of service (DoS). Open switch ports, Wi-Fi that leaks outside the building, rogue access points and missing firewalls all raise the risk.

Key terms

  • ARP poisoning
  • MAC spoofing
  • MAC flooding
  • on-path (man-in-the-middle) attack
  • DNS poisoning
  • denial of service (DoS/DDoS)
Read the review notes: 3.1 Network Vulnerabilities and Attacks

A few quick questions on this topic, with the answers explained.

Network policies set minimum rules for routers, switches, VPNs and Wi-Fi, such as banning local accounts, turning off unneeded services like Telnet, requiring port security and MAC filtering, and forbidding split tunneling. For Wi-Fi, you can turn off beacon frames, limit the signal's strength and direction, require users to sign in, and use strong encryption. WEP, WPS and the original WPA are insecure; the course framework (fall 2026) names WPA3 as the strongest option.

Key terms

  • router and switch security policy
  • port security
  • MAC filtering
  • split tunneling
  • beacon frame
  • WPA3
  • Wireless Security Settings - CompTIA Security+ SY0-701 - 4.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • WiFi (Wireless) Password Security - WEP, WPA, WPA2, WPA3, WPS Explained

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

  • Port Security - CompTIA Security+ SY0-701 - 3.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • Next-Gen Wi-Fi Security - WPA3 Explained

    TechquickieWatch on YouTube (opens in a new tab)

  • What is split tunneling? Here are the pros and cons

    TECHtalkWatch on YouTube (opens in a new tab)

Read the review notes: 3.2 Protecting Networks: Managerial Controls and Wireless Security

A few quick questions on this topic, with the answers explained.

Segmentation splits a network into smaller, isolated pieces so an attack on one part can't easily spread. You can segment with subnets (based on IP addresses), with VLANs set up on switches, and with a screened subnet, or DMZ, that holds public-facing servers between the internet and the private network. Each segment can then get its own security level.

Key terms

  • network segmentation
  • subnet
  • VLAN
  • screened subnet (DMZ)
  • security zone
  • Segmentation and Access Control - CompTIA Security+ SY0-701 - 2.5

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is a DMZ? (Demilitarized Zone)

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

  • What are VLANs? -- the simplest explanation

    Practical NetworkingWatch on YouTube (opens in a new tab)

  • Understanding Cybersecurity: Network Segmentation

    Intelligence QuestWatch on YouTube (opens in a new tab)

  • Subnets vs VLANs

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

Read the review notes: 3.3 Protecting Networks: Segmentation

A few quick questions on this topic, with the answers explained.

A stateless firewall filters on packet details like IP addresses, ports and protocols. A stateful firewall also tracks connections, and a next-generation firewall (NGFW) adds deep packet inspection, intrusion prevention and filtering by application. A firewall follows an access control list (ACL) read from the top, and the first matching rule wins, so rule order matters. You want a firewall on each segment and on every connection to the internet.

Key terms

  • stateless firewall
  • stateful firewall
  • next-generation firewall (NGFW)
  • access control list (ACL)
  • rule order
  • inbound vs. outbound traffic
Read the review notes: 3.4 Protecting Networks: Firewalls

A few quick questions on this topic, with the answers explained.

A network intrusion detection system (NIDS) raises alerts, and an intrusion prevention system (NIPS) can also block traffic. A SIEM pulls logs from many sources together to spot patterns, with AI helping sort them. Signature-based detection is fast with almost no false positives but misses brand-new attacks; anomaly-based detection compares traffic to a normal baseline and can catch new attacks, but it costs more and raises more false alarms, and hybrid detection combines both. In logs, watch for known-bad IP addresses, scans, traffic spikes or a port used by the wrong application.

Key terms

  • NIDS vs. NIPS
  • SIEM
  • signature-based detection
  • anomaly-based detection
  • false positive and alert fatigue
  • indicator of compromise (IoC)
Read the review notes: 3.5 Detecting Network Attacks

A few quick questions on this topic, with the answers explained.