Exam objective

SY0-701 3.2: Secure Enterprise Infrastructure

Security+ Topic

Secure Enterprise Infrastructure for Security+

This Security+ topic covers infrastructure placement reasoning: device placement, security zones, attack surface, and connectivity; Failure and device behavior: fail-open, fail-closed, active, passive, inline, tap, and monitor attributes; Network security appliance roles: jump server, proxy server, IPS, IDS, load balancer, and sensors; Port and firewall architecture: port security, 802.1X, EAP, WAF, UTM, NGFW, Layer 4, and Layer 7.

Start first lesson

5 lessons in this topic

Common mistakes to avoid

1

Learners often choose a security device based only on its name and ignore placement. The correction is to ask what traffic the device must see or control. Another common confusion is treating a security zone as a product.

2

Learners often confuse IDS with IPS only by name, but the deeper distinction is passive observation versus active prevention.

3

Learners often confuse IDS and IPS. The shortest correction is detection versus prevention: IDS alerts, IPS can block. Learners also sometimes choose a proxy for any security function.

4

Learners often choose WAF for any firewall question. The correction is that WAF is specific to web application traffic. Another common confusion is Layer 4 versus Layer 7: Layer 4 uses ports and protocols, while Layer 7 understands application content or behav...