TechKnowSurge
VideoSecurityFree

What are Endpoints?

Endpoint security starts with understanding which devices on a network require protection and how to harden them against attack. This covers the full scope of endpoints — from workstations and servers to mobile devices, IoT systems, and managed network infrastructure.

Complete this video to capture a CTF flag worth 1 point.

About this video

Endpoint security begins with a clear understanding of what constitutes an endpoint and which devices on a network require protection. In networking, all connected devices are considered nodes, and these fall into two categories: end devices and intermediary devices. End devices — including workstations, laptops, desktops, servers, mobile devices, and IoT systems — sit at the edges of the network and serve as the source or destination of data. Intermediary devices such as routers, switches, and firewalls facilitate the movement of that data between end devices. From a security perspective, end devices are the primary focus because they store and process the assets most worth protecting. However, managed intermediary devices also present exploitable attack surfaces and must be addressed as part of a comprehensive security strategy. Unmanaged switches offer little configuration surface and are generally lower priority, but any device that can be accessed and configured warrants attention. Hardening is the practice of locking down devices to make them resilient against attack — reducing vulnerabilities, eliminating unnecessary services, and enforcing secure configurations. The full scope of devices requiring hardening includes workstations, laptops, virtual desktop infrastructure, servers, mobile phones and tablets, IoT and embedded systems such as SCADA and industrial control systems, network devices including routers, switches, and firewalls, and cloud infrastructure. Any device with a presence on the network should be evaluated for how it can be hardened to reduce organizational risk.

What you'll learn

What's covered

Endpoint Security

Key terms

Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
Internet of Things
IoT
A network of physical devices embedded with sensors and software that connect and exchange data over the internet.
Server
A computer or program that provides services or resources to other devices, known as clients, over a network.
Router
A network device that forwards data packets between networks based on IP addresses.
Switch
A network device that connects devices within a LAN and forwards traffic based on MAC addresses.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Hardening
The process of securing a system by reducing its attack surface — disabling unnecessary services, applying configuration best practices, removing default credentials, and keeping software patched. Hardened systems offer fewer opportunities for exploitation.
Intermediary Device
A network node, such as a switch or router, that interconnects end devices and facilitates communication between them rather than serving as a source or destination of traffic.
End Device
A network node that acts as the source or destination of data, such as a workstation, server, or mobile device.

Topics

Endpoint Security Network Devices Device Hardening Iot Security Mobile Device Management Cybersecurity

Transcript

Nodes, end devices and intermediary devices

What are these endpoints? Let's make sure we have a good definition of what these endpoints are, so we get a scope of what we're talking about.

Let's first get into what nodes are when it comes to networking. Nodes are any devices that are going to send, receive, transfer or pass on any kind of network communication. So in this case right here, we've got computers that are sending and receiving, servers, switches, routers — any of these devices are all nodes on this network.

We can essentially break down nodes into two different categories: intermediary devices and end devices. End devices are all of these devices that are sitting at the end of the network that are really built to send and receive the data. They're either the source or the destination of most of our traffic. Then what we have is the intermediary devices. Intermediary devices are the switches and the routers that are helping facilitate this communication.

So here we have a PC right here that's communicating to this server right here. These are the end devices within here. And then the intermediary devices are what is transferring the data back and forth between these devices.

What we are trying to protect

From a cyber security perspective, this is mainly what we're trying to protect. We have these resources here — these endpoints, or you hear me call them endpoints or end devices. These end devices or endpoints are what's transferring the data, but they're also what stores that asset, and so these are largely what we're trying to protect.

What we want to do is go through the process of hardening these devices. Hardening is when we're securing these, when we're locking them down, when we're making sure that they're going to be resilient to an attack, so if they get attacked, they're not going to be susceptible to those types of attack. So we want to go through a hardening process to be able to secure these devices.

Including intermediary devices

The thing is that we have intermediary devices that could be susceptible to certain types of attacks as well, and because of that we want to harden those as well. So for the purpose of this module, we're going to actually include these inside of our endpoints. When we're talking about hardening endpoints, we're also talking about hardening these intermediary devices, if they're something that can be managed and something that we can get into.

Usually routers — almost always routers — we're managing those. Those are something that can be manageable, so we need to harden those devices. If a switch is a managed switch, then we need to harden those as well. If it's an unmanaged switch, then maybe we don't need to be as concerned about that.

Devices to consider hardening

So we're going to be really talking about hardening these different devices and what steps we can do to do that, and we're going to include a lot of these intermediary devices. Here's a list of those devices that we would want to consider hardening:

  • computer devices, workstations, laptops, desktops
  • virtual desktop infrastructure
  • servers
  • IoT devices like industrial control systems or SCADA systems or embedded systems
  • mobile devices, phones and tablets
  • network devices like switches, routers, firewalls
  • cloud infrastructure

Any device that's sitting on our network, we want to start thinking about how we would go about hardening those.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →