TechKnowSurge
ISC2 CC 4.1 NIST 800-53 SI-4 CompTIA Network+ 4.3 CompTIA Security+ 3.2 ISC2 CC 4.2 NIST 800-53 IA-3 NIST 800-53 SC-26 Cisco CCST Cybersecurity 2.3
InteractiveSecurityFree

Pick the Network Defense

Detect it, block it, filter it, lock the port, check the device, or set a trap? Pick the control.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Six controls from the lesson, and what each one is for. IDS and IPS. An intrusion detection system notices attacks and suspicious behavior and tells you. An intrusion prevention system also takes action, blocking what it detects. (The video says "intrusion protection"; the usual name is intrusion prevention.) Why not always prevent? Anything that judges behavior has false positives, and an IPS in front of your web servers that wrongly blocks customers is a business problem. A network-based IDS or IPS (NIDS, NIPS) watches network traffic; a host-based one runs on a single machine. Proxy server. Users' web requests go to the proxy, which fetches the content and passes it on. That lets it block sites ("you can't go there"), scan what comes back for viruses, and control the flow. Port security. Set on a switch, port by port, to control which devices may use each port, so someone who gets into the building cannot just plug in. Network access control (NAC). Valid credentials are not enough: is the machine patched, is its antivirus up to date? NAC checks the device's state and keeps it off the network until it meets the requirements. It is one way to put zero trust into practice: no device is trusted just because it is inside the building, and it is checked again, not only once. Deception. A honeypot is a decoy machine in its own segment; a honeynet is a whole decoy network; a honey file is a tempting file no real user needs; a honey token is any decoy data. None is real, so anyone who touches one is suspect, and you watch how they work.

What you'll learn

Aligned to

ISC2 CC
4.1 Understand network security
4.2 Understand network security architecture
NIST 800-53
SI-4 System Monitoring
IA-3 Device Identification and Authentication
SC-26 Decoys
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions.
CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
Cisco CCST Cybersecurity
2.3 Describe network infrastructure and technologies

Key terms

Intrusion Detection System
IDS
A system that monitors network or system activities for malicious behavior and generates alerts.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
False Positive
An alert that fires when no actual issue exists, which over time can cause administrators to ignore notifications and reduce monitoring effectiveness.
Proxy Server
An intermediary server that handles requests between clients and other servers, providing anonymity and content filtering.
Web Filtering
A security mechanism that controls which websites users can access by blocking or allowing URLs based on defined policies.
Port Security
A Cisco switch feature that restricts which devices can connect to a port by limiting the number of allowed MAC addresses or requiring specific MAC addresses to be present. When a violation occurs, the port can be configured to shut down, restrict traffic, or send an alert.
Network Access Control
NAC
Network Access Control enforces security policy on devices attempting to connect to a network, verifying compliance with posture requirements such as patch level, antivirus status, and certificate validity before granting access.
Zero Trust
A security model that assumes no user or device is trusted by default and requires continuous verification.
Honeypot
A decoy system or network designed to attract and detect attackers while logging their activity.
Honeynet
A decoy network of systems designed to attract attackers and monitor their behavior across an entire simulated environment.
Honey File
A decoy file placed within a system to detect unauthorized access by attracting and tracking adversary interaction.
Honey Token
A piece of deceptive data or a digital artifact placed in a system to detect unauthorized access or misuse by attracting and tracking attacker activity.

Topics

Intrusion Prevention System Network Access Control Honeypot Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →