TechKnowSurge
VideoSecurityFree

Endpoint Security

Endpoint security architecture covers the built-in technologies, configuration practices, protective software, and maintenance procedures that keep networked devices secure. Central to this process is hardening — a structured set of steps applied to each device to reduce vulnerabilities before and after deployment.

Complete this video to capture a CTF flag worth 1 point.

About this video

Endpoint security is built on four foundational pillars: leveraging built-in security technologies, applying secure configurations, installing protective software, and maintaining and monitoring systems over time. Built-in features like the Trusted Platform Module offer hardware-rooted security that requires little or no additional setup, while configuration work — disabling unnecessary ports, stripping default software, and adjusting factory settings — directly reduces the attack surface of each device. On the protection side, host-based firewalls and intrusion prevention systems help guard individual endpoints against threats, and on the maintenance side, patch management, group policy enforcement, logging, and performance monitoring keep security posture from degrading over time. Unifying these pillars is the concept of hardening — a deliberate, step-by-step process applied to a device before it enters production use. Most hardware and software ships in a permissive default state designed for ease of use rather than security, which means a newly received laptop, switch, or router is rarely ready to deploy without intervention. Hardening corrects that gap by systematically tightening configurations and removing unnecessary functionality. While specific hardening procedures vary by device type, manufacturer, and even model — with many vendors publishing dedicated hardening guides for their products — a consistent set of general principles applies across the majority of endpoint devices and forms the practical foundation for any endpoint security strategy.

What you'll learn

What's covered

Endpoint Security Overview

Key terms

Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.
Hardening
The process of securing a system by reducing its attack surface — disabling unnecessary services, applying configuration best practices, removing default credentials, and keeping software patched. Hardened systems offer fewer opportunities for exploitation.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Trusted Platform Module
TPM
Trusted Platform Module is a dedicated hardware security chip embedded in devices that provides a hardware root of trust for secure boot, cryptographic key storage, and platform attestation, protecting sensitive keys from software-level compromise.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Log Management
The process of collecting, storing, analyzing, and monitoring log data generated by systems and applications.

Topics

Endpoint Security Device Hardening Security Controls Cybersecurity Configuration Management Vulnerability Reduction

Transcript

When we're architecting security for our endpoints, we need to think about that big picture, the big picture of security around those endpoints.

Aspects of Endpoint Security

When it comes to security, here are some of the devices that we're going to want to make sure remain secure on our network, and here's some of the different aspects that I think about when securing these endpoints.

There's some built-in technologies that we may or may not have to do anything about, that is, they could come preconfigured or pre-installed, or the technology is part of whatever it is that we're implementing. So there are some built-in features that allow us to do some security.

Then how we configure those devices makes a big difference on how secure those devices are. Of course, there's some things that we are going to want to do to protect those systems, like software to be installed on them. There's also some maintenance and monitoring that we're going to want to do to make sure that they maintain a certain level of security. Although this maintenance and this monitoring, I cover that more in depth in a whole other course, so we're not going to hit those as heavily, but we're really going to focus on the built-in technologies and how to configure and protect these different end devices.

Examples in Each Category

Here are some examples of each one of these categories:

  • For built-in, something like a trusted platform module, which is a chip installed on machines to help make sure that there is a certain level of security involved on those machines.
  • As far as configurations, we might want to disable ports or change the default settings. We might want to remove extra software or extra features that are installed, so we would want to configure the machines.
  • From a protection standpoint, we'd want to make sure that there's a firewall installed, or some sort of intrusion protection system installed on the host.
  • With maintenance, we'd want to go through patching. Maybe we apply some sort of group policy to these.
  • And then monitoring: we want to make sure that we're logging and checking performance and checking software on these machines.

So we want to make sure that these bases are all covered.

The Hardening Process

One way we do that is through a hardening process. A hardening process is these steps that we go through in order to make sure a machine is protected. Let's say we receive a laptop. We've ordered a laptop and we receive that laptop. Now we're going to want to go through a process to deploy that laptop. We're going to go through a hardening process to make sure that that laptop is more secure, that it's hardened against certain threats that are out there.

One of the reasons why this is necessary is because machines often come to us outdated or not set up for proper security. A good example of that is when you receive a new switch. They want it to work for you. They don't want you to plug it in and have to do a bunch of extra stuff and then think that, oh well, it's broken and so I'm going to send it back. So instead, it comes in working order, and it's not the most secure. So we go through this hardening process to start locking things down to make it more secure.

Hardening Is Device-Specific

For each one of our devices, there's going to be a separate process, or separate steps, that we're going to do to harden those devices. For instance, a certain piece of hardware like a router: we would want to go through certain steps to harden a router. Even more specifically, if it's a Cisco router, there's probably more specific steps that we would use to harden a Cisco router. And then if it is a specific type of router from Cisco, there's probably even a paper out there on what we need to do to harden that device. So depending on what the manufacturer is, and what product it is, and what specific model it is, there are steps that we want to go through to harden those devices.

For the most part, we're going to be talking about hardening as general rules, general processes that we would follow that would apply to a lot of these devices, if not all of those devices.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →