CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – Protocols

Protocols – a standard set of rules that determines how computers communicate with each other across networks despite their differences

Layered architecture

  • Shows how communication should take place
  • Clarify the general functions of a communication process
  • To break down complex networking processes into more manageable sub-layers
  • Using industry standard interfaces enables interoperability
  • To change the features of one layer without changing the code in every layer
  • Easier troubleshooting

Planning to take the CISSP Exam?

Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only $25.00.

Click the Add To Cart Button to Purchase

Click the Add To Cart Button to Purchase

Plus you will also get copies of notes from other CISSPs.

Learn more about this package by visiting this blog entry: CISSP REVIEW NOTES I USED TO PASS THE EXAM.

CLICK BELOW TO MAKE YOUR PURCHASE NOW.

All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.

IMPORTANT NOTICE:

I MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE WILL BE SOME DELAY ON YOU RECEIVING AN E-MAIL FROM ME WITH THE LINK TO THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME WITHIN 24-48 HOURS.

Open Systems Interconnect (OSI) Model

Layer 7 – Application

  • Responsible for all application-to-application communications
  • User information maintained at this layer is user data
  • Security: Confidentiality, Authentication, Data Integrity, Non-repudiation
  • Technology: Gateways
  • Protocols: FTP, SMB, Telnet, TFTP, SMTP, HTTP, NNTP, CDP, GOPHER, SNMP, NDS, AFP, SAP, NCP, SET

Layer 6 – Presentation

  • Responsible for the formatting of the data so that it is suitable for presentation
  • Responsible for character conversion (ASCII/EBCDIC)
  • Encryption/Decryption, Compressions and Virtual Terminal Emulation
  • User information maintained at this layer is called messages
  • Security: Confidentiality, Authentication, Encryption
  • Technology: Gateway
  • Protocols: ASCII, EBCDIC, Postscript, JPEG, MPEG, GIF

Layer 5 – Session

  • Responsible for the setup of the links, maintaining of the link and the link tear-down between applications
  • Security: None
  • Technology: Gateway
  • Protocols: Remote Procedure Calls (RPC), SQL, RADIUS, DNS, ASP

Layer 4 – Transport

  • Responsible for the guaranteed delivery of user information
  • Also responsible for error detection, correction and flow control
  • User information at this layer is called datagram
  • Security: Confidentiality, Authentication, Integrity
  • Technology: Gateway
  • Protocols: TCP, UDP, SSL, SSH-2, SPX, NetBIOS, ATP

Layer 3 – Network

  • Responsible for the routing of user data from one node to another through the network including the path selection
  • Logical addresses are used at this layer
  • User information maintained at this layer is called packets
  • Security: Confidentiality, Authentication, Data Integrity
  • Technology: Virtual Circuits (ATM), routers
  • Protocols: IP, IPX, ICMP, OSPF, IGRP, EIGRP, RIP, BOOTP, DHCP, ISIS, ZIP, DDP, X.25

Layer 2 – Data Link

  • Responsible for the physical addressing of the network via MAC addresses
  • There are two sublevels: MAC & LLC
  • Has error detection, frame ordering and flow control
  • User information maintained at this layer is called frames
  • Security: Confidentiality
  • Technology: Bridges, switches
  • Protocols: L2F, PPTP, L2TP, PPP, SLIP, ARP, RARP, SLARP, IARP, SNAP, BAP, CHAP, LCP, LZS, MLP, Frame Relay, Annex A, Annex D, HDLC, BPDU, LAPD, ISL, ,MAC, Ethernet, Token Ring, FDDI

Layer 1 – Physical

  • Responsible for the physical transmission of the binary digits through the physical medium
  • Includes things such as the physical cables, interfaces and data rate specifications
  • User information maintained at this layer is called bits
  • Security: Confidentiality
  • Technology: ISDN, Hubs, Repeaters, Cables
Bookmark and Share

Business & Tech News Update

ISuppli: HTC's Droid Incredible Costs $163 to Make

A teardown analysis shows HTC's Incredible is incredibly similar to the Nexus One, the Android phone from Google

Amazon Bets the Kindle Will Grow

The best-selling Kindle will be at the center of Amazon's digital media strategy. Says CEO Bezos: "There's going to be a generation 10 and a generation 20"

Behind Disney's Digital Shopping Spree

The purchase of game maker Playdom may help Disney's brands with the Facebook generation

Comments

Leave a Reply




  • Your Shopping Cart

    Your cart is empty
  • Calendar

    January 2010
    M T W T F S S
    « Dec   Feb »
     123
    45678910
    11121314151617
    18192021222324
    25262728293031
  • RSS e-Business News from eCommerceTimes

    • AT&T Is Winning Its Catch-Up Race
      AT&T Mobility and Apple iPhone have been successful together, but every coin has two sides. The other side has been a wireless data logjam. Could that problem finally be getting under control? AT&T has been working very hard to do just that, said Ralph de la Vega, AT&T mobility and consumer markets president and CEO, at last week's Fortune B […]
    • Europe's Tender Words About FOSS
      There's no denying that everyone needs a little love from time to time, but for those of us in the FOSS community, that need can be particularly acute. After all, rarely a week goes by without some affront from those we had hoped were our friends. Case in point? Dell. Imagine our surprise, then -- nay, outright joy! -- when none other than Neelie Kroes […]
    • PRM: It's Not Just CRM for Partners
      CRM is a complex thing. It involves understanding your customers and your own business -- two difficult things to fully grasp under any circumstances -- and then using technology to convert that understanding into a positive impact on your business. Customers, and to a lesser extent your business, are always changing. […]
    • Senate Committee Hacks Away at Online Privacy Thicket
      The pressure on major Web site operators and online advertisers to do a better job of protecting consumers' privacy continues to mount. On Tuesday, Senator John Kerry, D-Mass., said he plans to introduce legislation that would "give people more control over how their personal information is collected and distributed online." […]
    • Why That Mountain of Leads Is a Molehill of Sales
      In the struggle to grow revenues in tighter markets, most companies are pushing their marketing departments to provide greater market coverage and deliver more sales opportunities. Yet statistics reveal that an astonishing 79 percent of leads generated by corporate marketing departments are never contacted by corporate sales groups. […]
    • The Beauty of a Sustainable Supply Chain
      The new age of sustainability is like a three-legged stool, and over the last couple of weeks I've discussed my ideas for the first two legs, including customers and energy or transportation. The third leg involves products, and this idea takes some thinking to fully comprehend. Most of us don't think a lot about products because they are ubiquito […]
    • Yahoo Japan May Succeed Where Yahoo Failed
      Yahoo Japan has announced that it will begin a relationship with Google to power its search functions and also administer ads that appear on the site. In this deal, the company is not following in the steps of its U.S. counterpart, Yahoo, which cut a deal with Microsoft's Bing, announced last year. […]
    • Citigroup Upgrades Careless iPhone Banking App
      Citigroup customers who do mobile banking on an iPhone should head to the Apple App Store immediately for an upgrade. A flaw in the Citigroup mobile banking iPhone app released in March 2009 causes personal information to be saved in a hidden file on the mobile device, the banking giant revealed in a letter to customers dated July 20, a day after it released […]
    • Doctoring the Customer Experience
      Retailers' worst nightmare has indeed come to bear: American consumers have permanently changed their buying habits, according to research by several firms. Gone are the days of shopping as a pastime. And, for all practical purposes, brand loyalty has just about evaporated. […]
    • IBM's Next-Gen 'System of Systems' Mainframe
      For most systems vendors, the launch of a next-generation server platform qualifies as a pretty big deal. After all, such occasions provide vendors multiple opportunities to strut their visionary stuff, roll out a host of satisfied customers, and highlight their current/future strategies. However, some next-gen platforms are -- literally and figuratively -- […]
  • RSS From the National Vulnerability Database

    • CVE-2009-4960 (lanai-core) July 27, 2010
      Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. […]
      nvd@nist.gov
    • CVE-2010-1577 (content_delivery_system, internet_streamer) July 27, 2010
      Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL. […]
      nvd@nist.gov
    • CVE-2009-4973 (totalcalendar) July 27, 2010
      SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action. […]
      nvd@nist.gov
    • CVE-2010-2703 (openview_network_node_manager) July 27, 2010
      Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe. […]
      nvd@nist.gov
    • CVE-2009-4972 (simpleid) July 27, 2010
      Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attackers to inject arbitrary web script or HTML via the s parameter. […]
      nvd@nist.gov
    • CVE-2010-0211 (openldap) July 27, 2010
      The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, […]
      nvd@nist.gov
    • CVE-2009-4971 (vjchat) July 27, 2010
      SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. […]
      nvd@nist.gov
    • CVE-2009-4958 (emo_breeder_manager) July 27, 2010
      SQL injection vulnerability in video.php in EMO Breader Manager allows remote attackers to execute arbitrary SQL commands via the idd parameter. […]
      nvd@nist.gov
    • CVE-2009-4970 (t3m_affiliate) July 27, 2010
      SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. […]
      nvd@nist.gov
    • CVE-2010-2529 (iputils) July 27, 2010
      Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafted echo response. […]
      nvd@nist.gov
Get Adobe Flash playerPlugin by wpburn.com wordpress themes