Exam objective
SY0-701 3.2: Secure Enterprise Infrastructure
Secure Enterprise Infrastructure for Security+
This Security+ topic covers infrastructure placement reasoning: device placement, security zones, attack surface, and connectivity; Failure and device behavior: fail-open, fail-closed, active, passive, inline, tap, and monitor attributes; Network security appliance roles: jump server, proxy server, IPS, IDS, load balancer, and sensors; Port and firewall architecture: port security, 802.1X, EAP, WAF, UTM, NGFW, Layer 4, and Layer 7.
Start first lesson5 lessons in this topic
Common mistakes to avoid
Learners often choose a security device based only on its name and ignore placement. The correction is to ask what traffic the device must see or control. Another common confusion is treating a security zone as a product.
Learners often confuse IDS with IPS only by name, but the deeper distinction is passive observation versus active prevention.
Learners often confuse IDS and IPS. The shortest correction is detection versus prevention: IDS alerts, IPS can block. Learners also sometimes choose a proxy for any security function.
Learners often choose WAF for any firewall question. The correction is that WAF is specific to web application traffic. Another common confusion is Layer 4 versus Layer 7: Layer 4 uses ports and protocols, while Layer 7 understands application content or behav...