Data Communication and Networking

Network Security Fundamentals; Firewall and IDS; VPN — Virtual Private Network

C-CAT

Network Security Fundamentals

Common Network Attacks

AttackDescription
DoS (Denial of Service)Overwhelm target with traffic to make it unavailable
DDoSDistributed DoS — from many compromised machines
MITM (Man-in-the-Middle)Attacker intercepts communication between two parties
PhishingTrick users into revealing credentials via fake websites
ARP SpoofingSend fake ARP replies to redirect traffic
DNS SpoofingRedirect domain names to malicious IPs
SQL InjectionInsert malicious SQL into application inputs
Port ScanningDiscover open ports and services (Nmap)
Sniffer/EavesdroppingCapture network traffic to read data
RansomwareEncrypt victim's files and demand ransom

Security Measures

MeasureDescription
EncryptionEncrypt data in transit (SSL/TLS, IPSec)
FirewallBlock unauthorized network traffic
IDS/IPSDetect/prevent intrusions
VPNEncrypted tunnel for remote access
Network segmentationIsolate sensitive network segments
Access controlAuthenticate and authorize users
Patch managementKeep systems updated
MonitoringLog and analyze network traffic

Firewall and IDS

Firewall

A firewall filters network traffic based on rules to allow or block packets.

Types:

TypeDescription
Packet FilterChecks source/destination IP, port, protocol
Stateful InspectionTracks connection state; allows return traffic
Application Layer (WAF)Inspects application-layer content
Next-Generation Firewall (NGFW)Combines all above with deep packet inspection

Firewall Rules:

Rule 1: Allow TCP to port 80 (HTTP) from any source → PERMIT
Rule 2: Allow TCP to port 443 (HTTPS) from any source → PERMIT
Rule 3: Allow TCP from 192.168.1.0/24 to any → PERMIT (internal outbound)
Rule 4: Deny all other traffic → DROP (default deny)

IDS vs IPS

FeatureIDSIPS
Full formIntrusion Detection SystemIntrusion Prevention System
ActionDetect and alertDetect and block
PositionPassive (mirror port)Inline
ResponseLogs and notifies adminAutomatically blocks traffic

VPN — Virtual Private Network

What is VPN?

A VPN creates an encrypted tunnel over the internet to connect remote users or sites to a private network securely.

Remote Worker → [Encrypted VPN Tunnel] → [VPN Gateway] → Corporate Network
(Home/Hotel)         Internet                               (Private)

VPN Types

TypeDescriptionUse Case
Site-to-Site VPNPermanent connection between two officesBranch office connectivity
Remote Access VPNTemporary connection for individual usersWork from home
SSL VPNVPN via web browser (port 443)Clientless access
IPSec VPNIP Security protocolMost enterprise VPNs

VPN Protocols

ProtocolSecuritySpeedNotes
OpenVPNHighModerateOpen-source, widely trusted
WireGuardHighFastModern, efficient
IPSec/IKEv2HighFastStandard enterprise protocol
L2TP/IPSecHighModerateCommon for mobile
PPTPLowFastOld, insecure — avoid

Continue learning

Related notes

Put this topic into timed practice

Open mock tests when you want full-exam pacing, or keep drilling in practice mode.