TechKnowSurge
ISC2 CC 4.2 ISC2 CC 1.4 NIST 800-53 SC-7 CompTIA Security+ 3.2 NIST 800-53 AC-6 CompTIA Network+ 4.3 CompTIA Security+ 4.5
InteractiveSecurityFree

Audit the Network Security Plan

Review TechKnowDJ's security plan for its new studio, layer by layer, and flag every line that leaves a gap.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Defense in depth means no single control has to be perfect: if one layer fails, the next one still stands. Securing Your Network builds the layers from the outside in. - The building: controlled access, equipment off the floor, cooling sized for the room so the temperature stays steady, a UPS and a generator, and devices wiped (their configurations too) before disposal. - The edge: a firewall whose zones keep public servers in the screened subnet, letting in only returning traffic and what ACL rules allow; an IDS or IPS (an IPS blocks, at the cost of false positives); a next-generation firewall that can block by application. - Inside: segments for departments, management traffic and IoT, with VLANs; zero trust, so no device is trusted just for being inside, with NAC checking each device's state and port security on the switches; decoys such as a honeypot to catch anyone poking around. - Wireless and remote access: the highest WPA version with 802.1X; guests kept apart; VPNs, with the split tunnel's trade-off understood; remote desktop through a jump box. - Every device: hardened to its baseline, the minimum standard for its kind; encrypted drives; no admin rights for everyday accounts; patch management; antivirus and EDR.

What you'll learn

Aligned to

ISC2 CC
4.2 Understand network security architecture
1.4 Understand cybersecurity controls
NIST 800-53
SC-7 Boundary Protection
AC-6 Least Privilege
CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
4.5 Given a scenario, modify enterprise capabilities to enhance security.
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions.

Key terms

Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Environmental Controls
Physical safeguards such as HVAC, fire suppression, and humidity regulation used to protect network equipment from environmental damage.
Asset Disposal
The process of securely decommissioning and discarding equipment, including wiping configurations and sanitizing devices to prevent data exposure.
Screened Subnet
A dedicated network segment that hosts publicly accessible services, isolating them from the internal network so that a compromised host cannot directly access internal resources.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
False Positive
An alert that fires when no actual issue exists, which over time can cause administrators to ignore notifications and reduce monitoring effectiveness.
Zero Trust
A security model that assumes no user or device is trusted by default and requires continuous verification.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Port Security
A Cisco switch feature that restricts which devices can connect to a port by limiting the number of allowed MAC addresses or requiring specific MAC addresses to be present. When a violation occurs, the port can be configured to shut down, restrict traffic, or send an alert.
Split Tunnel
A VPN configuration that routes only traffic destined for the private network through the VPN tunnel, while other traffic takes a direct internet path.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.

Topics

Defense In Depth Zero Trust Network Segmentation Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →