Pods for Certs
Master the Certifications. Build the Career.
Studying for an IT certification can feel overwhelming. Hundreds of pages of study material, countless technical concepts, and limited time to fit it all into a busy schedule.
That's where this podcast comes in.
Each episode takes a focused section of an industry-recognized certification exam and transforms it into a practical, engaging discussion designed to help you learn smarter. Instead of trying to absorb an entire certification at once, you'll tackle one exam objective at a time—making it easier to understand, retain, and apply what you're learning.
From CompTIA A+, Network+, and Security+ to Linux Essentials, cloud technologies, networking, cybersecurity, and beyond, every episode is built around the official exam objectives published by the certification providers themselves. You'll get targeted coverage of the topics employers value and certification exams demand.
Whether you're studying during your commute, listening between projects, reinforcing classroom training, or preparing for exam day, this podcast helps you turn spare moments into productive learning opportunities.
No unnecessary fluff. No endless theory. Just focused, certification-aligned content designed to help you gain confidence, strengthen your technical knowledge, and move one step closer to your next certification.
If your goal is to break into IT, advance your career, increase your earning potential, or stay current in a rapidly changing technology landscape, subscribe now and start learning one objective, one episode, and one certification at a time.
Your next certification starts here.
Pods for Certs
Network+ Section 4: Network Plus Security Attacks and Defenses
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
CompTIA Network+ (N10-009)
The guide(s) referenced in this material can be found at the following link: https://www.etsy.com/shop/MountainRangeMedia
15% off at the shop on orders $25 or more! https://mountainrangemedia.etsy.com?coupon=MRMPODS15
New episodes release every Wednesday!
This podcast, based on the Mountain Range Media Sectional Study Guides, provides a comprehensive overview of the Network Security domain for the CompTIA Network+ certification. It emphasizes foundational security principles such as the CIA triad, Zero Trust, and the implementation of multi-factor authentication through protocols like RADIUS and TACACS+. The material meticulously categorizes various network threats, ranging from social engineering and wireless attacks to Layer 2 exploits like ARP spoofing. To counter these risks, the text details technical defenses including firewall configurations, switch-port hardening, and the use of encryption. Readers are encouraged to master symptom-to-defense pairings to effectively identify and mitigate infrastructure vulnerabilities. Ultimately, the guide serves as a practical roadmap for applying layered security controls to protect modern network environments.
Intro & Outro info:
Music Licensor's Username: paulyudin-27739282
Licensee: u_x32f6b3u3b
Audio File Title: Tech Corporate
Provided courtesy of: https://pixabay.com
Voice provided courtesy of: venice.ai voice - Callum
Podcast audio hosts provided courtesy of: Notebook LM
Disclaimer
Mountain Range Media is an independent publisher of educational content and is not affiliated with, endorsed by, or sponsored by the Linux Professional Institute (LPI), CompTIA, Anthropic, Google, OpenAI, Etsy, or any of their products, services, certification programs, or platforms. References to third-party trademarks, certifications, products, and services are for identification and educational purposes only and remain the property of their respective owners. All content reflects the views of Mountain Range Media alone. Use of these materials does not guarantee passing any examination, earning any certification, obtaining employment, or achieving any particular result.
Imagine building like a multimillion dollar smart house.
Speaker 2Right.
Speaker 1We're talking integrated climate control, automated lighting, uh fiber optic internet wired into literally every single room.
Speaker 2Sounds pretty nice, honestly.
Speaker 1You spend months perfecting this whole infrastructure. But then you just you decide not to put locks on the doors, or I don't know, maybe you just leave the master key sitting right there on the welcome mat.
Speaker 2Yeah, which obviously defeats the entire purpose of the house.
Speaker 1Exactly. And that is exactly what it's like building a modern enterprise network without mastering domain 4.0. So welcome back, everyone, to the fourth deep dive in our special five-part series designed specifically to help you crush the ComTIA network plus exam.
Speaker 2Glad to be back.
Speaker 1We spent, you know, the last three sessions building your network house, the cabling, the IP addressing, the routing, but today we are finally putting the locks on the doors.
Speaker 2And it is uh it's entirely foundational. Just to set the stage for you. Domain 4.0 is network security. And this makes up a massive 18% of the exam.
Speaker 118%? That's huge.
Speaker 2It really is. Yeah. Now we know network plus is not strictly a security exam. Right. I mean, CompAA has security plus for the deep cyber operations stuff. But a modern network simply cannot function without security woven into its very fabric. It's not an add-on anymore.
Speaker 1It's just part of the job. And to make sure you are getting the absolute best information as you study, today's material is drawn directly from the study guides by Mountain Range Media. You can find them on their Etsy shop. Uh quick note: this is an independent resource, so it's not affiliated with CompTIA, but it is purpose-built to get you certified.
Speaker 2It's a great resource. And the strategy you really need to adopt for this specific domain, it's all about identifying causality.
Speaker 1Causality, like cause and effect.
Speaker 2Exactly. The exam won't just ask for simple textbook definitions. It's going to test your ability to uh read a scenario, identify the symptom, diagnose the specific attack happening, and then prescribe the exact defense.
Speaker 1Okay, so matching the symptom to the attack and the attack to the defense.
Speaker 2Precisely. If you can understand the mechanisms of how these attacks and defenses interact, I mean you will absolutely excel here.
Speaker 1So before we start plugging in firewalls and you know writing access lists, we really need to understand the, I guess, philosophical goal here. Like what are we actually trying to protect when we secure a network?
Speaker 2Well, everything comes back to a core framework. It's called the CIA triad.
Speaker 1CIA. Like the agency.
Speaker 2Right. But in this case, it stands for confidentiality, integrity, and availability. Every single control you put in place serve at least one of these three masters.
Speaker 1Okay, so break those down for me.
Speaker 2Sure. So confidentiality means only authorized eyes get to see the data. Think encryption. Integrity ensures there are no unauthorized modifications, basically. What was sent is exactly what was received.
Speaker 1Got it. And availability.
Speaker 2I mean that sounds self-explanatory, but it just means the network and its resources are actually there when authorized users need them. You could have like a perfectly secure server that's disconnected and buried under 10 feet of concrete.
Speaker 1Right. Good luck hacking that.
Speaker 2Exactly. It's highly confidential. It has perfect integrity, but it utterly fails the availability test because nobody can actually use it.
Speaker 1Oh, that makes sense. So if we map that back to like a high security office building, confidentiality is the badge reader at the front door. Integrity is maybe the tamper evidence seal on a classified envelope. And availability is just making sure the elevators are actually powered on so people can get to their desks.
Speaker 2That is a really solid way to visualize it.
Speaker 1But you know, if we're going with the office building analogy, I kind of have to push back on how networks traditionally operate.
Speaker 2Oh, how so?
Speaker 1Well, if I've already swiped my badge past the security guard and I'm physically sitting at a desk inside the building, shouldn't the internal network just trust me? I mean, I'm already inside the perimeter.
Speaker 2See, what you're describing is the old castle and moat approach to network security. And honestly, it is incredibly dangerous today. Really? Why? Because the assumption used to be that if you were on the inside, you were trusted. But once an attacker breaches that outer moat, say, by I don't know, compromising a single laptop with a phishing email, they have free reign to move laterally across the entire internal network.
Speaker 1Oh, wow. Because everyone just assumes they're supposed to be there.
Speaker 2Right. And that inherent vulnerability is exactly why modern networks rely on a principle called zero trust.
Speaker 1Zero trust, meaning the network is essentially just paranoid.
Speaker 2Yeah, but it's a necessary paranoia. Zero trust means never trust, always verify. Your physical or logical location on the network grants you zero implicit trust.
Speaker 1So even if I'm like literally plugged directly into a switch in the CEO's private office.
Speaker 2Yes. Even then, the network treats your device as potentially hostile until you authenticate and authorize every single request you make.
Speaker 1Okay, so for everyone studying, when you're sitting in the exam room and you see a scenario prioritizing, never trust, always verify, your brain should immediately lock in on zero trust.
Speaker 2Exactly. Look for those buzzwords.
Speaker 1But how does that play out practically? It sounds like an administrative nightmare if everyone has access to everything but has to verify it constantly.
Speaker 2Well, the catch is they don't have access to everything. And that's the next critical piece of the puzzle. Least privilege.
Speaker 1Least privilege, meaning giving them the bare minimum.
Speaker 2Exactly. You grant a user or even a system only the absolute minimum access required to do their specific job and nothing more. If a user only needs to read a database file, you strictly deny right access. But what if that one restriction fails? Like what if someone bypasses it? That's why we use defense in depth.
Speaker 1Okay, layering things.
Speaker 2Right. We layer multiple independent security controls. So if an attacker bypasses the firewall, they still hit the internal access controls. If they bypass those, the data itself is still encrypted.
Speaker 1So a failure in one layer doesn't just ruin the whole system.
Speaker 2Exactly. And we combine that with separation of duties, which is basically splitting critical tasks across different people.
Speaker 1Like the person who requests a firewall rule change can't be the same person who approves and implements it.
Speaker 2Spot on. It prevents abuse.
Speaker 1Okay. That gives us the blueprint. We know we aren't trusting anyone, no matter where they are. But how does the network actually verify who someone is and what they are allowed to do every single time they try to click a link?
Speaker 2This relies on the AAA framework. That's authentication, authorization, and accounting.
Speaker 1You know, this feels exactly like dealing with security at a really exclusive nightclub.
Speaker 2Oh, I like this. Go on.
Speaker 1Well, authentication is the bouncer looking at your driver's license, right? Verifying, yes, you are who you claim to be. Authorization is the bouncer checking his clipboard and saying, okay, you have general admission, but you don't have a VIP wristband. You can go to the bar, but you cannot go to the VIP lounge. Right. And accounting is the bartender keeping a meticulous tab of every single drink you order all night so there's an actual record of what you did. Trevor Burrus, Jr.
Speaker 2It works exactly like that. Now, for the exam, you need to understand the technical mechanisms we use to build that bouncer. Multifactor authentication or MFA is pretty much standard now. Right.
Speaker 1That's where you need more than just a password.
Speaker 2Exactly. It forces the user to provide at least two different categories of evidence: something you know, like a password, something you have like a hardware token or an authenticator app on your phone, and something you are, like a biometric fingerprint or a face scan.
Speaker 1But asking for an authenticator code for every single internal network request, I mean that would completely paralyze a company. Nobody would get any work done. How do corporate environments handle authentication seamlessly behind the scenes?
Speaker 2Well, in Windows environments, they heavily rely on a protocol called Kerberos. It's a ticket-based authentication protocol, and it operates on port 88.
Speaker 1Port 88, good to remember.
Speaker 2Yeah. So instead of sending your password across the network every single time you request a file, Kerberos authenticates you once and hands you a timestamped ticket, granting ticket. You just show that ticket to access services.
Speaker 1Wait, let me stop you at timestamped. Why does time matter so much for Kerberos? I've heard that if my laptop clock is off by like five minutes, it completely breaks my network access. Why is that?
Speaker 2It's because of replay attacks.
Speaker 1Replay attacks.
Speaker 2Yeah. So if an attacker intercepts your ticket while it's traveling across the network, they could theoretically try to send it again later to impersonate you. But by strictly enforcing time synchronization, usually within a tight five-minute window, the Cabrero server ensures that any captured tickets are almost immediately rendered invalid.
Speaker 1Oh wow. So if the attacker tries to use it 10 minutes later, the the server just says, nope, ticket expired.
Speaker 2Exactly.
Speaker 1That makes total sense. What about when you first plug a device into the wall? Because you mentioned zero trust means the switch port itself doesn't trust you.
Speaker 2Right. And that is handled by 802.1x, which is court-based network access control.
Speaker 1802.1x.
Speaker 2Yes. When you plug in, the switch port is essentially dead to normal network traffic. It acts as an authenticator. Your laptop acts as the supplicant, sending your credentials through the switch to an external authentication server.
Speaker 1So I literally cannot send standard data traffic until that external server validates me.
Speaker 2Correct. The server validates you and then tells the switch port, okay, open up for this device.
Speaker 1And you know, in modern networks, we don't want to log in 50 times a day across a bunch of different web apps either. That's where SSO single sign-on comes in, right? Allowing one login to grant access to your email, your HR portals, your databases. Yep. And SAML is the underlying web protocol that actually federates that identity across all those different platforms.
Speaker 2Exactly right. Now, regarding those external authentication servers we just mentioned, for 802.1x, you're going to encounter two major protocols on the exam, Radius and TechAS plus Vump.
Speaker 1Oh yes. I definitely want to drill into this. What is the practical difference when an administrator is, you know, choosing between Radius and TechAS plus Vump?
Speaker 2Let's break down how they operate. So Radius runs on UDP ports 1812 and 1813. It is incredibly common for basic network access, like just getting a user onto corporate Wi-Fi. Okay.
Speaker 1UDP. So it's fast, but maybe not perfectly reliable.
Speaker 2Right. But mechanically, Radius only encrypts the password in the access request packet. The rest of the payload, including the username, is sent in clear text. And furthermore, Radius bundles authentication and authorization together.
Speaker 1Oh, so it's a package deal. And TacAS Plus fixes that.
Speaker 2Exactly. TACAS Plus is a Cisco developed protocol that runs on TCP port 49, making it highly reliable. And it encrypts the entire payload of the packet, not just the password. But its real superpower is that it completely separates authentication from authorization.
Speaker 1Meaning you can control exactly what an administrator does after they log in.
Speaker 2Yes, through what's called per command authorization. With CACAS Plus Plus, you can tell a router, look, this junior admin is allowed to log in, but they are only authorized to run show commands. If they try to type a reload command, deny it.
Speaker 1Wow. So you have granular control.
Speaker 2Exactly. Radius cannot do that. So if an exam scenario asks about device administration with per command control, the answer is always TACAS Plus Plus.
Speaker 1Good to know. Okay, so we've verified identities. We still need to physically and logically separate our general admission users from our VIPs, going back to the club analogy. And we do that through network segmentation, right? Using VLANs to isolate broadcast domains and subnets to contain traffic. That way, if the marketing department gets compromised, the attacker can't just casually slide over to the accounting server.
Speaker 2Precisely. We also use screen subnets, which you might know is a DMZ.
Speaker 1Demilitarized zone.
Speaker 2Yep. If you have a web server that the public internet actually needs to access, you place it in a screen subnet. It's basically an isolated buffer zone sitting between the untrusted internet and your highly trusted internal LAN. And we control the traffic crossing these boundaries with ACL's access control lists.
Speaker 1And remember, for everyone listening, routers read ACLs strictly from the top down, and the first match wins.
Speaker 2That's a crucial point.
Speaker 1Yeah. Like if rule number one says deny this IP, the router drops the packet immediately. It doesn't matter if rule number 50 would have permitted it. And there's always that implicit deny at the very bottom. If your traffic doesn't explicitly match a permit rule, it just gets dropped.
Speaker 2Absolutely. So we have our zero trust philosophy, our strong AA bouncers, and our segmentation. But as we know, attackers still find ways in. Domain 4.0 really requires you to understand the exact mechanisms of these attacks.
Speaker 1Right. And we won't insult your intelligence by like defining what a phishing email or a smishing text message is. You know, social engineering targets the human element because, well, human psychology is a lot easier to manipulate than a firewall.
Speaker 2Much easier.
Speaker 1Attackers use urgency or authority to trick users into handing over credentials. But let's dive into the technical layer. Let's look at layer two attacks.
Speaker 2Okay, one of the most fascinating mechanisms here is VLAN hopping.
Speaker 1VLAN hopping.
Speaker 2Yeah. So segmentation is supposed to keep traffic separate, right? But an attacker can bypass this by crafting a frame with two VLAN tags instead of one. When the frame hits the first switch, the switch reads the outer tag, which belongs to the native VLAN, strips it off, and forwards it along the trunk link.
Speaker 1And because it stripped that first tag, the hidden second tag is now exposed.
Speaker 2Exactly. The receiving switch reads that second malicious tag, and suddenly the attacker's traffic is forwarded directly into a restricted VLAN they never should have had access to.
Speaker 1I was so sneaky. Okay, here's an attack I really want you to break down for me. MAC flooding. Because a network switch is intelligent, right? It directs traffic only to the specific port where the destination device lives. So how does pumping thousands of fake MAC addresses into a switch actually help an attacker steal data?
Speaker 2It exploits a hardware limitation. The switch uses a CAM table content addressable memory to map MAC addresses to physical ports. But that memory is finite. It has a limit. Right. If an attacker uses a tool to just blast tens of thousands of forged MAC addresses at the switch in seconds, that memory fills up instantly.
Speaker 1So what does the switch do when it's totally out of memory? Does it just crash?
Speaker 2No, it does something actually worse from a security perspective. It fails open.
Speaker 1Fails open.
Speaker 2Yeah. Once the CAM table is full, the switch can no longer intelligently route frames. So it basically panics and reverts to acting like a basic dumb network hub. It takes every single incoming frame and broadcasts it out of every single port.
Speaker 1Oh wow. So the attacker just sits there with a packet sniffer and watches all the network's private traffic stream right into their laptop.
Speaker 2Exactly. It forces the switch into a state where it just shouts everyone's secrets out loud.
Speaker 1That is wild. What about on-path attacks, what we used to call uh man in the middle? How do they secretly intercept traffic?
Speaker 2Often through ARP spoofing. ARP, the address resolution protocol, is inherently trusting. It resolves IP addresses to physical MAC addresses. An attacker can send a gratuitous ARP reply to a victim's machine.
Speaker 1Gratuitous meaning nobody asked for it.
Speaker 2Right. It's essentially saying, hey, the IP address of the default gateway router now belongs to my MAC address. The victim's machine blindly accepts this and updates its ARP cache.
Speaker 1So now every time the victim tries to send traffic out to the internet.
Speaker 2It flows directly through the attacker's machine first.
Speaker 1Crazy. And we see a similar mechanism with DNS poisoning, but just at a higher layer, right?
Speaker 2The attacker corrupts the DNS resolver's cache. So when a user types in their bank's URL, the poison cache translates that name into the IP address of a malicious server that's built to look exactly like the real bank. The user types in their password and it goes straight to the attacker.
Speaker 1You also need to be ready for wireless attacks on the exam. You might see a scenario where an attacker spins up a rogue wireless access point with the exact same SSID or network name as the corporate Wi-Fi. That is called an evil twin. Yes. But wait, how do they actually get people to connect to the evil twin if their laptops are already connected to the real Wi-Fi?
Speaker 2By using a deauthentication attack. The attacker sends forged wireless management frames to the victim's device, spoofing the real access point and basically saying you need to disconnect. The victim gets kicked off the real network.
Speaker 1And then their device automatically tries to reconnect.
Speaker 2Exactly. And when it does, the attacker captures the four-way handshake, which they can then take offline and run a brute force dictionary attack against to crack the password.
Speaker 1Man. And we can't forget malware, specifically ransomware, which you know encrypts an organization's data and demands payment for the decryption key. But okay, we've seen how the network breaks. Let's talk about the arsenal. How do we actually fix all this?
Speaker 2Let's start at the perimeter boundaries with firewalls. You really need to understand the mechanism difference between stateless and stateful firewalls. Okay, let's hear it. A stateless firewall is essentially just a simple packet filter. It looks at every single packet in a vacuum against an ACL. It has absolutely no memory of what happened a millisecond ago.
Speaker 1Which isn't very smart.
Speaker 2Right. A stateful firewall, however, maintains a state table. It tracks the actual context of a conversation. If an internal user initiates a web request out to a server, the stateful firewall remembers that connection.
Speaker 1So when the external server sends the traffic back, the firewall knows it's part of an established legitimate session and just lets it through without needing a specific inbound rule.
Speaker 2Exactly. Modern networks take this even further with NGFW's next generation firewalls, which add deep packet inspection and application level awareness to block specific activities, like, say, uploading to file sharing sites.
Speaker 1Many of those NGFWs also integrate intrusion detection and prevention. Let's clarify IDS versus IPS. An intrusion detection system is passive, right? It watches a copy of the traffic and sends an alert if it sees a malicious signature. An intrusion prevention system sits in line, right in the actual flow of traffic, and actively blocks the malicious packets.
Speaker 2Correct.
Speaker 1But wait, if an IPS actually stops the attack dead in its tracks, why would anyone ever bother with an IDS? Why risk letting the malicious packet through just to get an email alert?
Speaker 2It comes back to availability. Because an IPS sits in line, it introduces a severe risk of false positives.
Speaker 1Oh, meaning it blocks good traffic by mistake.
Speaker 2Exactly. If its signature database misidentifies highly unusual but legitimate internal traffic as an attack, it will drop those packets. Imagine a hospital network where an IPS misclassifies a massive uncompressed MRI image transfer as a buffer overflow attack. Oh wow. Right, and it drops the data while a surgeon is waiting for the operating room. In highly sensitive environments where availability is paramount, an out-of-band IDS is much safer. It alerts the security team to investigate without ever risking the interruption of critical business flows.
Speaker 1That's a huge point. Now, for the layer two defenses, this is where you really need to link the attacks we just discussed to their direct countermeasures. ComTIA will test you heavily on this. This is exam gold.
Speaker 2Yes, let's run through them. If the attack is MAC flooding, where they are trying to overflow that CAM table we talked about, your defense is port security. Port security. You configure the switch to only allow a specific number of MAC addresses per physical port. If the switch detects a sudden flood of unknown MAC addresses, it instantly shuts down the port, stopping the attack at the physical layer.
Speaker 1Okay, what if the attacker is running a rogue DHCP server, handing out bad default gateways to intercept traffic?
Speaker 2Your defense there is DHCP snooping. This is a mechanism where you tell the switch which specific uplink ports are actually trusted to send DHCP offers, usually the ports directly connected to your actual servers.
Speaker 1So every other port facing a normal user is deemed untrusted.
Speaker 2Right. And if a DHCP offer packet originates from an untrusted user port, the switch drops it immediately.
Speaker 1And DHCP snooping actually builds a database of legitimate IP to MAC bindings, right?
Speaker 2Yeah.
Speaker 1Which brings us to ARP spoofing. If an attacker is sending forged ARP replies.
Speaker 2You defend with dynamic ARP inspection or DAI, it literally relies on the database created by DHCP Snoop. But they work together. They do. When a switch receives an ARP reply claiming to own an IP address, DAI checks that binding database. If the MSC address doesn't perfectly match the legitimate IP assignment, the switch knows it's a spoof packet and drops it.
Speaker 1And finally, if an attacker plugs a rogue switch into a wall jack and tries to manipulate your spanning tree protocol to become the root bridge and intercept traffic, you defend with BPDU guard. If a regular user port receives a switch management frame, a BPDU, the switch immediately disables the port.
Speaker 2Exactly. Beyond the switch, you also need to understand how we secure the data in transit, cryptography. You need to know how symmetric and asymmetric encryption pair together.
Speaker 1Right. Symmetric encryption, like AES, uses the exact same key to encrypt and decrypt the data. It's incredibly fast and great for encrypting large amounts of data, like a whole hard drive. But the problem is, how do I securely send you that secret key across the internet without someone intercepting it?
Speaker 2And that is the exact problem asymmetric encryption solves. Algorithms like RSA or ECC use a mathematically linked key pair. There's a public key that you share with the world and a private key that you keep secret. Anyone can use your public key to encrypt a message, but only your specific private key can decrypt it.
Speaker 1So in a secure web connection, my browser uses the server's asymmetric public key to securely encrypt and send over a fast symmetric session key. And then they just use that symmetric key for the rest of the conversation.
Speaker 2Precisely. And we verify the integrity of that data using hashing, like the SHA 256 algorithm. A hash is a one-way mathematical function. It creates a unique fixed-length signature for a file. You cannot decrypt a hash.
Speaker 1Right. It's just a fingerprint.
Speaker 2Exactly. If you download a file and your generated hash matches the author's hash perfectly, you are with absolute mathematical certainty that the file was not altered in transit.
Speaker 1And all of this is managed by a PKI, a public key infrastructure, using a certificate authority to issue digital certificates that tie a public key to a verified identity. It's basically what makes HTTPS work. And lastly, we have physical security. Because the best firewalls in the world are useless if someone can just walk straight into the server room. We use man traps, those small access vestibules where the first door must close and lock completely before the inner door will open to prevent tailgating.
Speaker 2It is the ultimate manifestation of defense in-depth. The man trap, the biometric badge reader, the firewall, the port security, the encryption. Every single layer just increases the friction for the attacker.
Speaker 1And with that, you have officially survived domain 4.0. We dove really deep today, but remember the core strategy for the test. Understand the mechanism of the attack and pair it directly to the mechanism of the defense. That is the key to passing this 18% chunk of the CompTIA network plus exam.
Speaker 2Definitely. And as a reminder, the highly detailed study guide powering this session is available from Mountain Range Media on Etsy. And of course, always verify these concepts against the current official Comp TIA exam objectives as you prepare for test day.
Speaker 1We have one final part left in our series. Next time we're bringing everything together with network troubleshooting. But before we go, I want to leave you with a puzzle to chew on.
Speaker 2Yeah, so we spent a lot of time today discussing zero trust. The architecture that assumes any device, even one hardwired into the corporate office, is potentially hostile. If that is true, and every single request must be individually authenticated and authorized regardless of its origin, is the traditional idea of building a massive expensive perimeter firewall around a physical office becoming t entirely obsolete. I mean, if the internal network is treated as hostile anyway, why do we even care where the perimeter is? Something to think about as you study.