Fortinet NSE-1
Lession-5 Insider Threat Perspectives
Q. Which practice strengthens the physical security of your work environment?
Select one:
Pile all confidential documents neatly to one corner of your desk.
Shred and destroy all documents that contain sensitive personal or organizational information rather than tossing them into the waste bin.
Ensure that your software is up-to-date and that the latest patches are applied.
Recycle all paper, CDs, DVDs, hard drives etc. into their appropriate bins.
Q. Which method is a defense against potential insider threats?
Select one:
Monitor your co-workers’ daily activities.
Identify and report any suspicious activity.
Investigate and if possible resolve the threat on your own.
Confront any person you suspect of being an insider threat.
Q.Identify two best practices for physical security awareness. (Choose two.)
Select one or more:
Follow your organization’s security policies unless they hinder efficiency.
Keep your desk free of any proprietary or confidential information.
Lock your computer screen and mobile devices every time you step away.
Always be considerate, such as holding the door open for people, even if you don’t know them.
Q. Who are included as insider threats?
Select one:
Another organization or person who see themselves as competitors
Ambitious people
Employees who sometimes do not follow security practices
Any person with network security skills who works outside an organization
Q. If a suspicious package appears at your desk, which action is best aligned with good physical security practices?
Select one:
Get your neighbour to open the package.
Carefully open the package and report what you find.
Report the package and do not open or touch it.
Destroy the package using an industrial shredder.
Fortinet NSE-1
Lesson 4—Internet Threat Perspectives
Q. Which three of the following activities represents data vulnerabilities on a mobile device. (Choose three.)
Select one or more:
Listening to music
Banking
Synchronization between computers and mobile devices
Social networking
Creating contacts
Q.Complete the sentence. A social engineering attack that compromises public charging stations and installs malware when a portable device plugs in, is known as
Select one:
Spearphishing
Phishing
Juice Jacking
Ransomware
Q Which of the following is a good habit for protecting your mobile device?
Select one:
Change the factory-set default password and username.
Set up a personal hotspot.
Test connectivity by doing online banking.
Configure your email accounts.
Q. Complete the sentence. Phishing attacks are different than spearphishing, whaling, and vishing because they
Select one:
use social media and social engineering techniques to lure their victims, while the others primary use email.
involve hackers hanging out at internet forums who then collect information about individuals to target, while the others are aimed at a wide audience.
are aimed at a wide audience, while the others are directed toward individuals or specific organizations.
are directed against smaller players—small fish you might say, while the others use social media sites.
Q.Which precaution should you take if you receive an email that involves the movement of money, such as the payment of an invoice, even if it is from someone you know?
Select one:
Use another form of trusted communication to verify that the message is legitimate.
Look for spelling mistakes in the email. If you find any, delete the email. It’s obviously a scam.
Pay it immediately to avoid late fees.
Reply to the email and ask them to provide proof of their identity
Fortinet NSE 1
Lession-1
Q. What component is necessary to form a botnet?
A. Command & Control Server (C&C)
Q. What is it called when a fraudulent email masquerades as a legitimate communication in an attempt to get a user to reveal sensitive information?
A. Phishing
Q. What is the goal of the Cyber Terrorist?
A. Intimidation through disruption and damage
Q. What is the motivation of the bad actor known as the "Explorer"?
A Notoriety
Q. What is the motivation of the "Cyber Terrorist"?
A. Ideology
Q. What is the motive of the "Cyber Criminal"?
A Money
Q. What is the name of the malware that takes over a computer system and holds hostage the disk drives or other data?
A. Ransomware
Q. What is the primary motive of the "Cyber Warrior"?
A. The political interest of their country's government
Q. Zero-day exploits
A. Attacking systems by exploiting otherwise unknown and unpatched vulnerabilities
Q. Primary motivations of the Hacktivist
A. Political, social, or moral disagreements
Free Free Free | Cyber Security Courses | Get Certification
Free Free Free | Cyber Security Courses | Get Certification
BGP State
Idle The BGP process is either administratively down or awaiting the next retry
attempt.
Connect The BGP process is waiting for the TCP connection to be completed. You
cannot determine from this state information whether the TCP connection
can complete.
Active The TCP connection has been completed, but no BGP messages have yet
been sent to the peer.
Opensent he TCP connection exists, and a BGP Open message has been sent to the
peer, but the matching Open message has not yet been received from the
other router.
Openconfirm An Open message has been both sent to and received from the other router.
The next step is to receive a BGP Keepalive message (to confirm that all
neighbor-related parameters match) or a BGP Notification message (to learn
that there is some mismatch in neighbor parameters).
Established ll neighbor parameters match, the neighbor relationship works, and the
peers can now exchange Update messages.
Cybersecurity Essentials | All Quiz Answer | Cisco Certification
Step-1 go to below link
https://www.netacad.com/courses/security
Step-2 Enroll and login
Step-3 complete course then quizzes
Step-4 get Certification
watch video complete
https://youtu.be/-xCVeKSIhHM
Now choose course and start quiz
Following video is related to Cybersecurity Essentials Course
https://youtu.be/-wSJ2qKkmFk
OSPF State
The adjacency building process takes effect after multiple stages have been fulfilled. Routers that
become adjacent will have the exact link-state database. The following is a brief summary of the
states an interface passes through before becoming adjacent to another router:
Down: No information has been received from anybody on the segment.
Attempt: On non-broadcast multi-access clouds such as Frame Relay and X.25, this state
indicates that no recent information has been received from the neighbor. An effort should be
made to contact the neighbor by sending Hello packets at the reduced rate PollInterval.
Init: The interface has detected a Hello packet coming from a neighbor but bi-directional
communication has not yet been established.
Two-way: There is bi-directional communication with a neighbor. The router has seen itself in
the Hello packets coming from a neighbor. At the end of this stage the DR and BDR election
would have been done. At the end of the 2way stage, routers will decide whether to proceed
in building an adjacency or not. The decision is based on whether one of the routers is a DR
or BDR or the link is a point-to-point or a virtual link.
Exstart: Routers are trying to establish the initial sequence number that is going to be used in
the information exchange packets. The sequence number insures that routers always get the
most recent information. One router will become the primary and the other will become
secondary. The primary router will poll the secondary for information.
Exchange: Routers will describe their entire link-state database by sending database
description packets. At this state, packets could be flooded to other interfaces on the router.
Loading: At this state, routers are finalizing the information exchange. Routers have built a
link-state request list and a link-state retransmission list. Any information that looks incomplete
or outdated will be put on the request list. Any update that is sent will be put on the
retransmission list until it gets acknowledged.
Full: At this state, the adjacency is complete. The neighboring routers are fully adjacent.
Adjacent routers will have a similar link-state database.
Linux certification || demanding certification || free of cost
Step-1 go to below link
https://training.linuxfoundation.org/resources/?_sft_content_type=free-course
Step-2 Registration then Enroll course
Step-3 Complete course and final exam
Step-4 Get certification
Watch complete video
https://youtu.be/VHMCtkh7m_0
Firewall
3.1 What is a Firewall
- Packet
filtering
- Stateful
packet filtering
- User
authentication
- Client
application authentication
3.2 Firewall Types
- Packet
filtering
- Application
gateway
- Circuit
level gateway
- Stateful
packet inspection
3.2.1 Packet Filtering Firewall
- What
types of protocols to allow (FTP, SMTP, POP3, etc.)
- What
source ports to allow
- What
destination ports to allow
- What
source IP addresses to allow (you can block certain IP addresses if you
wish)
3.2.2 Stateful Packet Inspection
- They
can tell whether the packet is part of an abnormally large stream of
packets from a particular IP address, thus indicating a possible DoS
attack in progress.
- They
can tell whether the packet has a source IP address that appears to come
from inside the firewall, thus indicating IP spoofing is in progress.
- They
can also look at the actual contents of the packet, allowing for some very
advanced filtering capabilities.
3.2.3 Application Gateway
3.2.4 Circuit Level Gateway
3.3 Firewall Implementation
- Network
host-based
- Dual-homed
host
- Router-based
firewall
- Screened
host
3.3.1 Host Based
- Ensuring
all patches are updated
- Uninstalling
unneeded applications or utilities
- Closing
unused ports
- Turning
off all unused services
3.3.2 Dual-Homed Hosts
3.3.3 Router-Based Firewall
3.3.4 Screened Hosts
3.4 Proxy Servers
3.4.1 NAT (Network Address Translation)
3.5 Windows Firewalls
- Domain: For those
computers authenticated on your domain.
- Public: For
computers from outside your network. You would treat outside traffic more
carefully than traffic coming from another machine in your domain.
- Private: Private
refers to traffic from your own computer, thus the term private.
- If
you do not explicitly need a port, then block it. For example, if you are
not running a web server on that machine, then block all inbound port 80
traffic. With home machines, you can usually block all ports. With
individual workstations on a network, you may need to keep some ports open
in order to allow various network utilities to access the machine.
- Unless
you have a compelling reason not to, always block ICMP traffic because
many utilities such as ping, tracert, and many port scanners use ICMP
packets. If you block ICMP traffic, you will prevent many port scanners
from scanning your system for vulnerabilities.
- Occasionally,
I would suggest continuing to write out acronyms such as ICMP just to make
sure this is reinforced.
3.7 Linux Firewalls
3.7.1 Iptables
- Packet
filtering: This
table is the essential part of the firewall. It is a packet filtering
firewall and it contains three standard chains: INPUT, OUTPUT, and
Forward. The INPUT chain processes incoming packets, and the OUTPUT chain
processes traffic sent out from the machine. If the firewall system is
also acting as a router, only the FORWARD chain applies to routed packets.
- Network
address translation: This table is used for performing
network address translation on outbound traffic that initiates a new
connection. This is used only if your machine is serving as a gateway or
proxy server.
- Packet
alteration: This
table is used only for specialized packet alteration. It is often called
the mangle table because it alters, or mangles, packets. It contains two
standard chains. This table might not even be needed for many standard
firewalls.
3.7.2 Iptables Configuration
- iptables
-F
- iptables
-N block
- iptables
-A block -m state --state ESTABLISHED,RELATED -j ACCEPT
- iptables
–L
- iptables
–A INPUT –p tcp –dport ssh –j ACCEPT
- iptables
–A INPUT –p tcp –dport 80 –j ACCEPT
3.8 Guided Exercise: Configuring iptables
Rules
|
Resources
|
|
|
Files
|
None
|
|
Machines
|
Ubuntu
Server
|
Login to Ubuntu Server and then run the command “sudo iptables -L”. It will ask for the user password. Enter the user password which is “Pa$$w0rd”, press enter and then it will show the current iptables rules.
Write the command “sudo iptables –A INPUT –p tcp --dport ssh –j ACCEPT” and if sudo asks for the user password enter “Pa$$w0rd”. Then run the command sudo iptables –L to list the iptables rules.
Write the command “sudo iptables –A INPUT –p tcp --dport 80 –j ACCEPT” and if sudo asks for the user password enter “Pa$$w0rd”. Then run the command sudo iptables –L to list the iptables rules.
To save the iptables rules run the command “sudo iptables-save”.
Type Of Attacks
2.1.1 SYN Flood
2.1.2 Smurf Attack
2.1.3 Ping of Death
2.1.4 UDP Flood
2.1.5 DoS Tools
2.2 Buffer Overflow Attacks
2.3 IP Spoofing
- Do
not reveal any information regarding your internal IP addresses. This
helps prevent those addresses from being “spoofed.”
- Monitor
incoming IP packets for signs of IP spoofing using network monitoring
software. One popular product is Netlog. This and similar products seek
incoming packets to the external interface that have both the source and
destination IP addresses in your local domain, which essentially means an
incoming packet that claims to be from inside the network, when it is
clearly coming from outside your network. Finding one means an attack is
underway.
- Routers
to external networks that support multiple internal interfaces
- Proxy
firewalls where the proxy applications use the source IP address for
authentication
- Routers
with two interfaces that support subnetting on the internal network
- Routers
that do not filter packets whose source address is in the local domain
2.4 Guided Exercise: Preventing IP Spoofing
Resources
|
|
Files
|
None
|
Machines
|
Ubuntu
Server
|


2.5 Session Hijacking
-
CCNA NEW BOOK CCNA 200-301 follow this blogger https://mega.nz/#!YgxmWShD key - aVCtCB_euTd-yeNqZAxCbZF5Nqdjni7Pu5fs8lqRizY ...
-
Route Redistribution - It is preferable to employ a single routing protocol in an internetwork environment, for simplicity and ease of m...
-
STP(Spanning Tree Protocol) Switching Loops A Layer-2 switch belongs to only one broadcast domain, and will forward both broadcasts and...