08. Network Segmentation Terms Flashcards

(42 cards)

1
Q

The IEEE standard that specifies how VLAN and trunking information appears in frames and how switches and bridges interpret that information.

A

802.1Q

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The interface on a switch used for an endpoint. Devices connected via this manner are unaware of VLAN information.

A

access port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A VM in a public subnet that can be remotely logged into and given privileged access to resources in a private subnet in the same VPC. Also called a jump box.

A

bastion host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A distributed storage structure that allows customers to store files in locations closer to where their users are located.

A

CDN (content delivery network)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A high-bandwidth link designed to support direct connections between data centers.

A

DCI (data center interconnect)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A preconfigured VLAN on a switch that cannot be renamed or deleted.

A

default VLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Networking resources that take advantage of globally distributed infrastructure and smaller data centers or partner network resources to deliver data and services closer to users before entering the public Internet infrastructure.

A

edge computing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An endpoint device or the device at the connection between networks.

A

edge device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A storage networking architecture that runs separately from Ethernet networks to maximize speed of data storage and access.

A

FC (Fibre Channel)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A technology that allows FC to travel over Ethernet hardware and connections.

A

FCoE (Fibre Channel over Ethernet)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The first four blocks or 64 bits of an IPv6 address that normally identify the network. Also called site prefix.

A

global routing prefix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A storage networking architecture that serves a few niche markets and falls on the difficult end of the installation and configuration spectrum.

A

IB (InfiniBand)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A virtual gateway device that provides a connection between internal, private resources and the public Internet.

A

IG (Internet Gateway)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

OT (operational technology) systems connected to the Internet.

A

IIoT (Industrial Internet of Things)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An IP address or broadcast address configured on a relay agent to direct UDP messages in support of UDP forwarding for centralized network services, such as DHCP, DNS, NTP, and TFTP.

A

IP helper address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A transport layer protocol used by SANs that runs on top of TCP to allow fast transmission over LANs, WANs, and the Internet.

A

iSCSI (Internet SCSI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

A VM in a public subnet that can be remotely logged into and given privileged access to resources in a private subnet in the same VPC. Also called a bastion host.

18
Q

A process of encapsulating layer 2 headers deeper within a packet, adjacent to higher layer headers.

A

layer 2 encapsulation

19
Q

The application of granular network zoning and object-level security for individual resources.

A

micro-segmentation

20
Q

The provision of multiple connections between servers and storage devices in a SAN (storage area network) to ensure quick failover and high-performance load balancing.

21
Q

A specialized storage device or group of storage devices that provides centralized, fault-tolerant file system storage and relies on network infrastructure to provide file access.

A

NAS (network attached storage)

22
Q

A logical appliance that performs NAT functions, providing filtered, protected access from resources in the private subnet to services on the Internet.

23
Q

A cloud-based subnet in which hosted resources are protected from Internet traffic.

A

private subnet

24
Q

A server acting as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.

25
A cloud-based subnet in which hosted resources are provided a direct route to the Internet.
public subnet
26
A networking device (such as a router or firewall) configured to support UDP forwarding.
relay agent
27
An area on the perimeter of a network that is surrounded by two firewalls—an external firewall porous enough to allow more types of traffic, and a hardened internal firewall that provides greater protection to the internal network. Formerly called DMZ (demilitarized zone).
screened subnet
28
The first four blocks or 64 bits of an IPv6 address that normally identify the network. Also called global routing prefix.
site prefix
29
A logical interface on a router that logically segments a single physical interface.
subinterface
30
A virtual interface on a switch used to handle inter-VLAN routing for all traffic directed at the switch’s virtual interface VLANs.
SVI (switch virtual interface or switched virtual interface)
31
A VLAN identifier added to a frame’s header according to specifications in the 802.1Q standard.
tag
32
The interface on a switch capable of managing traffic from multiple VLANs.
trunk port
33
The aggregation of multiple logical connections in one physical connection between connectivity devices. In the case of VLANs, a trunk allows switches to manage and exchange data between multiple VLANs across a single interface.
trunking
34
A network segment with strict rules for filtering traffic and no direct access to the Internet. Also called a private zone.
trusted zone
35
The ability of a router, firewall, layer 3 switch, or other relay agent to forward UDP traffic to support centralized network services such as DHCP, DNS, NTP, and TFTP.
UDP forwarding
36
Any network segment outside an organization’s control, such as the Internet. Also called a public zone or WAN zone.
untrusted zone
37
A network within a network that is logically defined by grouping ports on a switch so that some of the local traffic on the switch is forced to be routed, thereby limiting the traffic to a smaller broadcast domain.
VLAN (virtual local area network or virtual LAN)
38
An attack in which the attacker generates transmissions that appear, to the switch, to belong to a protected VLAN.
VLAN hopping
39
A subnetting method that allows subnets to be further subdivided into smaller and smaller groupings until each subnet is about the same size as the needed IP address space.
VLSM (Variable Length Subnet Mask)
40
A VLAN designed specifically to support VoIP traffic, which requires high bandwidths, priority over other traffic, flexible routing, and minimized latency.
voice VLAN
41
A software-defined portion of a larger, cloud-based network.
VPC (virtual private cloud)
42
A transport layer segmentation technology that inserts the MAC address next to the UDP header, essentially creating a layer 2 network overlay above layer 3.
VXLAN (virtual extensible LAN)