FCP Network Security Fundamentals & Fortinet Solutions — Questions and Answers
Question 1: What is the primary goal of network security?
- Increase network speed.
- Protect data & resources (Correct answer)
- Reduce bandwidth usage.
- Disable firewalls.
Correct answer: Protect data & resources
The primary goal of network security is to protect the integrity, confidentiality, and availability of data and network resources from unauthorized access, misuse, modification, or destruction. This involves implementing various controls and technologies to defend against cyber threats and ensure the network operates securely and reliably. It's about safeguarding valuable information and systems.
Question 2: What is a firewall?
- A device to increase speed.
- Filters traffic & blocks access (Correct answer)
- A wireless router.
- A type of virus.
Correct answer: Filters traffic & blocks access
A firewall is a network security device, either hardware or software, that monitors and controls incoming and outgoing network traffic based on predetermined security rules. Its main function is to establish a barrier between a trusted internal network and untrusted external networks, such as the internet, by filtering traffic and blocking unauthorized access attempts. This helps protect the network from various cyber threats.
Question 3: What is VPN used for?
- Increase internet speed.
- Secure remote access (Correct answer)
- Disable security.
- Monitor emails.
Correct answer: Secure remote access
A Virtual Private Network (VPN) creates a secure, encrypted connection over a less secure network, like the internet. Its primary use is to provide secure remote access, allowing users to connect to a private network (e.g., a corporate network) from a remote location as if they were physically present. This ensures data privacy and integrity when transmitting sensitive information.
Question 4: What is a common type of network attack?
- Software update.
- Denial of Service attack (Correct answer)
- File download.
- Email.
Correct answer: Denial of Service attack
A Denial of Service (DoS) attack is a common type of network attack where an attacker attempts to make a machine or network resource unavailable to its intended users. This is typically achieved by overwhelming the target with a flood of traffic or by exploiting a vulnerability that causes the system to crash, thereby disrupting normal service. Distributed Denial of Service (DDoS) attacks use multiple compromised systems to launch the attack.
Question 5: What does Fortinet provide?
- Hardware only.
- Cybersecurity solutions (Correct answer)
- Web hosting.
- Software games.
Correct answer: Cybersecurity solutions
Fortinet is a leading global provider of broad, integrated, and automated cybersecurity solutions. They offer a wide range of products and services, including firewalls (FortiGate), endpoint security, secure Wi-Fi, and cloud security, all designed to protect organizations from evolving cyber threats. Their focus is entirely on enterprise-level network and system security.
Question 6: What is threat intelligence?
- Weather updates.
- Cyber threat info (Correct answer)
- Network speed.
- User passwords.
Correct answer: Cyber threat info
Threat intelligence refers to organized, analyzed, and refined information about potential or existing cyber threats that can be used to understand, predict, and counter attacks. It provides insights into attacker motives, methods, and targets, enabling organizations to make informed security decisions and proactively defend against specific threats. This goes beyond raw data to provide actionable knowledge.
Question 7: How does multi-factor authentication enhance security?
- Reduces security.
- Multiple verification forms (Correct answer)
- Increases password reuse.
- Eliminates passwords.
Correct answer: Multiple verification forms
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more different forms of verification to gain access. Instead of just a password, MFA might require something you know (password), something you have (phone, token), and/or something you are (biometrics). This layered approach makes it much harder for unauthorized users to access accounts, even if one factor is compromised.
Question 8: What is a zero-day vulnerability?
- A scheduled update.
- Unknown exploitable flaw (Correct answer)
- Password reset.
- Firewall rule.
Correct answer: Unknown exploitable flaw
A zero-day vulnerability is a software flaw that is unknown to the vendor and for which no patch or fix has been publicly released. Attackers can exploit these vulnerabilities on 'day zero' of their discovery, before developers have a chance to address them, making them particularly dangerous. Organizations are highly vulnerable to zero-day exploits until a patch becomes available.
Question 9: Why is network segmentation important?
- Increases network traffic.
- Limits access & impact (Correct answer)
- Eliminates all threats.
- Reduces encryption.
Correct answer: Limits access & impact
Network segmentation divides a network into smaller, isolated segments, each with its own security policies. This is important because it limits unauthorized access to sensitive areas and contains the impact of a security breach. If one segment is compromised, the attack is less likely to spread to other parts of the network, thereby reducing the overall damage and improving security posture.
What is the primary goal of network security?