P-TECH IT

Domain 4 — Network Security

Lesson 4 · Domain 4 — Network Security · Download .docx

Objectives

Key terms

stateful firewall
Firewall that tracks connection state — allows return traffic for established sessions only.
NGFW
Next-Generation Firewall — adds application-layer inspection, IPS, and SSL/TLS decryption.
DMZ
Demilitarized Zone — screened subnet hosting public-facing servers, isolated from the internal LAN.
IDS
Intrusion Detection System — passive; detects and alerts but does not block traffic.
IPS
Intrusion Prevention System — inline; actively drops malicious traffic in real time.
defense in depth
Multiple overlapping security layers so no single failure exposes the entire system.
honeypot
Decoy system attracting attackers — defenders observe TTPs without risking production systems.
NAC
Network Access Control — checks device posture (patch level, AV status) before granting network access.
microsegmentation
Granular internal security zones preventing lateral movement if one segment is compromised.
ARP poisoning
Sending fake ARP replies to redirect traffic through the attacker's device (man-in-the-middle).
DAI
Dynamic ARP Inspection — switch feature that validates ARP packets against the DHCP snooping table.
802.1X
IEEE port-based Network Access Control — EAP authentication required before LAN access is granted.

The concept

FIREWALL TYPES AND ARCHITECTURE

Firewalls are the primary network perimeter control. Packet-filtering firewalls (stateless ACLs) examine source/destination IP and port on each packet independently — they cannot distinguish return traffic from an attack. Stateful firewalls maintain a connection state table: when an internal host initiates a TCP session, the firewall records it and automatically allows the return traffic without a separate rule. Next-Generation Firewalls (NGFW) add application identification (blocking BitTorrent even on port 443), integrated IPS signatures, and SSL/TLS decryption to inspect encrypted traffic for threats. The DMZ architecture places public-facing servers (web, email, DNS) in a screened subnet between two firewalls. An attacker compromising the web server in the DMZ hits the second firewall before reaching the internal LAN.

IDS, IPS, AND DECEPTION TECHNOLOGIES

An Intrusion Detection System (IDS) operates out-of-band (passive) — it receives a copy of traffic from a span port and generates alerts for suspicious patterns but cannot block anything. An Intrusion Prevention System (IPS) is inline — it sits in the traffic path and can drop packets matching attack signatures in real time. A honeypot is a decoy system intentionally deployed to attract attackers. When an attacker interacts with the honeypot, security teams observe their tools and techniques without risk to real systems. Honeynet extends this concept to a network of honeypots. Network Access Control (NAC) checks endpoint posture — OS patch level, antivirus currency, certificate validity — and quarantines non-compliant devices to a remediation VLAN.

DEFENSE IN DEPTH AND MICROSEGMENTATION

Defense in depth layers controls so that defeating any single layer does not fully expose the system: perimeter (firewall), network (VLAN segmentation, IPS), host (antivirus, EDR), data (encryption), user (MFA, least privilege). Microsegmentation extends this inside the data center or campus — east-west traffic between workloads is controlled by internal firewalls or SDN policies, not just the perimeter firewall. A compromised VM in one microsegment cannot freely reach adjacent segments without passing another security control, limiting lateral movement.

ARP ATTACKS AND DEFENSE

ARP has no authentication — any device can broadcast gratuitous ARP replies claiming to own any IP. ARP poisoning overwrites the ARP caches of victim devices to redirect their traffic to the attacker's MAC address (man-in-the-middle). Dynamic ARP Inspection (DAI) on managed switches validates every ARP packet on untrusted ports against the DHCP snooping binding table. If the claimed IP-to-MAC mapping does not match, DAI drops the packet and logs the event. Wireless-specific attacks include rogue APs (unauthorized devices connected to the wired network), evil twin APs (same SSID as legitimate, capturing traffic), and deauthentication floods (forcing clients off the legitimate AP to drive them to the evil twin).

Standards alignment: CompTIA Network+ Objective 4.1 (Security); Maryland Blueprint College and Career Readiness — Technology and Engineering.

Worked examples

Example 1: A security analyst reviews firewall logs and sees repeated connection attempts from an external IP to port 443 on the web server in the DMZ. The NGFW's application inspection identifies the traffic as an automated scanning tool, not HTTPS. The NGFW blocks the source IP based on the application signature — a stateless ACL only checking port 443 would have allowed it through. This demonstrates the value of NGFW application identification over basic port-based rules.
Example 2: Two workstations on the same VLAN report intermittent connectivity. Arp -a on each shows the gateway's IP (10.0.0.1) mapped to two different MAC addresses that keep changing. An ARP poisoning attack is in progress — a third host is broadcasting fake ARP replies. The network team enables Dynamic ARP Inspection (DAI) on the switch. DAI validates all ARP packets against the DHCP snooping table and drops the attacker's fake replies. Within seconds, the ARP caches stabilize and connectivity is restored.

Common mistakes

Self-check

Try each one before you look. A miss here costs nothing and tells you exactly what to reread.

1. What distinguishes a stateful firewall from a packet-filtering firewall?
2. An IDS differs from an IPS in that an IDS:
3. Dynamic ARP Inspection (DAI) protects against ARP poisoning by:
4. An evil twin attack involves:
5. Defense in depth means:

Canvas is the official record. This companion enhances the PGCC curriculum; it does not replace it. Last name and class year only. Students with a 504 plan or IEP: your accommodations apply.

← Domain 3 — Network OperationsDomain 5 — Network Troubleshooting →

↑ Back to top