This page is intentionally left blank Introduction to Networking with Network1 Timothy Pintello Credits VP & PUBLISHER Don Fowley EXECUTIVE EDITOR John Kane EDITOR Bryan Gambrel DIRECTOR OF SALES Mitchell Beaton EXECUTIVE MARKETING MANAGER Chris Ruel EDITORIAL PROGRAM ASSISTANT Jennifer Lartz SENIOR PRODUCTION & MANUFACTURING MANAGER Janis Soo ASSOCIATE PRODUCTION MANAGER Joel Balbin ASSISTANT MARKETING MANAGER Debbie Martin CREATIVE DIRECTOR Harry Nolan COVER DESIGNER Jim O’Shea TECHNOLOGY AND MEDIA Tom Kulesa/Wendy Ashenberg COVER PHOTO Arthur Kwiatkowski /Getty Images, Inc This book was set in Garamond by Aptara®, Inc. and printed and bound by Bind-Rite Robbinsville. The cover was printed by Bind-Rite Robbinsville. Copyright © 2013 by John Wiley & Sons, Inc.
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, Inc. 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030-5774, (201) 748-6011, fax (201) 748-6008.
To order books or for customer service, please call 1-800-CALL WILEY (225-5945). Microsoft, ActiveX, Excel, InfoPath, Microsoft Press, MSDN, OneNote, Outlook, PivotChart, PivotTable, PowerPoint, SharePoint, SQL Server, Visio, Windows, Windows Mobile, Windows Server, Windows Vista, and Windows 7 are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. Other product and company names mentioned herein may be the trademarks of their respective owners. The example companies, organizations, products, domain names, e-mail addresses, logos, people, places, and events depicted herein are fictitious.
No association with any real company, organization, product, domain name, e-mail address, logo, person, place, or event is intended or should be inferred. The book expresses the author’s views and opinions. The information contained in this book is provided without any express, statutory, or implied warranties. Neither the authors, John Wiley & Sons, Inc., nor their resellers or distributors will be held liable for any damages caused or alleged to be caused either directly or indirectly by this book.
Evaluation copies are provided to qualified academics and professionals for review purposes only, for use in their courses during the next academic year. These copies are licensed and may not be sold or transferred to a third party. Upon completion of the review period, please return the evaluation copy to Wiley. Return instructions and a free of charge return shipping label are available at www.com/go/returnlabel.
Outside of the United States, please contact your local representative. ISBN 9780470487327 Printed in the United States of America 10 9 8 7 6 5 4 3 2 1 www.com/college/ or call the Toll-Free Number: 1+(888) 764-7001 (U. & Canada only) Preface Welcome to Introduction to Networking with Network1. Wiley aims produce a series of textbooks that deliver compelling and innovative teaching solutions to instructors and superior learning experiences for students.
Crafted by a publisher known worldwide for the pedagogical quality of its products, these textbooks maximize skills transfer in minimum time. Students are challenged to reach their potential by using their new technical skills as highly productive members of the workforce. ■ The Wiley Program Introduction to Networking with Network1 includes a complete program for instructors and institutions to prepare and deliver a fundamentals of networking course and prepare students for CompTIA’s Network1 certification exam. We recognize that, because of the rapid pace of change in networking technology and changes in the CompTIA Network1 curriculum, there is an ongoing set of needs beyond classroom instruction tools for an instructor to be ready to teach the course.
Our program endeavors to provide solutions for all these needs in a system- atic manner in order to ensure a successful and rewarding course experience for both instructor and student—technical and curriculum training for instructor readiness with new software releases; the software itself for student use at home for building hands-on skills, assessment, and validation of skill development; and a great set of tools for delivering instruction in the classroom and lab. All are important to the smooth delivery of an interesting introduction to networking course, and all are provided with the Wiley technology program. We think about the model below as a gauge for ensuring that we completely support you in your goal of teaching a great course. As you evaluate your instructional materials options, you may wish to use the model for comparison purposes with available products.com/college/ or call the Toll-Free Number: 1+(888) 764-7001 (U.
& Canada only) | iii www.com/college/ or call the Toll-Free Number: 1+(888) 764-7001 (U. & Canada only) Illustrated Book Tour ■ Pedagogical Features Introduction to Networking with Network1 is designed to cover all the learning objectives for the Network1 exam, which is referred to as its “exam objectives.” The Network1 exam objectives are highlighted throughout the textbook. Many pedagogical features have been developed specifically for our Wiley information technology titles. Presenting the extensive procedural information and technical concepts woven throughout the textbook raises challenges for the student and instructor alike.
The Illustrated Book Tour that follows provides a guide to the rich features available with Introduction to Networking with Network1. Following is a list of key features in each lesson designed to prepare students for success on the certification exams and in the workplace: • Each lesson begins with an Exam Objective Matrix. More than a standard list of learning objectives, the Exam Objective Matrix correlates each software skill covered in the lesson to the specific Network1 exam objective. • Illustrations: Screen images provide visual feedback as students work through the exercises.
The images reinforce key concepts, provide visual clues about the steps, and allow students to check their progress. • Key Terms: Important technical vocabulary is listed at the beginning of the lesson. When these terms are first used later in the lesson, they appear in bold italic type and are defined. • Engaging point-of-use Reader aids, located throughout the lessons, tell students why this topic is relevant (The Bottom Line), provide students with helpful hints (Take Note), or show alternate ways to accomplish tasks (Another Way).
Reader aids also provide additional relevant or background information that adds value to the lesson. • Certification Ready features throughout the text signal students where a specific certification objective is covered. They provide students with a chance to check their understanding of that particular Network1 exam objective and, if necessary, review the section of the lesson where it is covered. • Knowledge Assessments provide progressively more challenging lesson-ending activities, including practice exercises and case scenarios.
• A Lab Manual is integrated with this textbook. The Lab Manual contains hands-on lab work corresponding to each of the lessons within the textbook. Numbered steps give detailed, step-by-step instructions to help students learn networking. The labs are constructed using real-world scenarios to mimic the tasks students will see in the workplace.com/college/ or call the Toll-Free Number: 1+(888) 764-7001 (U.
& Canada only) | v vi | Illustrated Book Tour ■ Lesson Features c09BasicNetworkSecurity.indd Page 285 1/26/12 1:33 PM user-f501 F-401 Basic Network LESSO N 9 Security E X A M O B J E C T I V E M AT R I X Exam Objective Matrix TECHNOLOGY SKILL COVERED EXAM OBJECTIVE EXAM OBJECTIVE NUMBER Network Security Considerations Basic Network Security Explain common threats, 5.4 Threats vulnerabilities, and mitigation techniques. • Wireless: • War driving • War chalking • WEP cracking • WPA cracking Business Scenario • Evil twin • Rogue access point c09BasicNetworkSecurity.indd Page 287 1/26/12 1:33 PM user-f501 F-401 • Attacks: • DoS • DDoS • Man in the middle • Social engineering • Virus Basic Network Security | 287 • Worms • Buffer overflow Allen Fox is the IT manager of a large call center. There have been a number of problems in his call • Packet sniffing • FTP bounce center related to basic security threats such as spyware and viruses. Allen determines that one way he • Smurf can minimize these problems is to educate the people who work in the call center about basic secu- Countering Basic Given a scenario, use the 4.
What things should Allen include in his education plan for the call center employees? Security Threats appropriate network monitoring resource to analyze traffic. • SNMP ■ Network Security Considerations • SNMPv2 • SNMPv3 Explain methods of user 5.3 Networking leaves computers susceptible to security threats. This lesson covers security authentication. threats, how to combat threats, and what to do after a security violation has taken place.
• PKI THE BOTTOM LINE If a computer is attached to a network in any way, it is vulnerable to outside attack. • Kerberos Therefore, if you have a network of any sort in your home or work, you need to take into • AAA (RADIUS, TACACS+) consideration what network security threats are there and how to deal with them. • Network access control (802.1x, posture assessment) The first step to minimize network security threats in a corporate or business environment is • CHAP to have a comprehensive network security policy for your business. Your policy should address • MS-CHAP the following security considerations: • What security threats does your organization have to combat? 285 • What can you do to combat a security threat? • What should you do after a security violation has taken place? This lesson deals with each of these considerations in detail.indd Page 286 1/26/12 1:33 PM user-f501 F-401 ■ Basic Network Security Threats This portion of Lesson 9 outlines the various threats that are typically seen on a computer connected to or on a network.
This section discusses various types of malicious software. 286 | Lesson 9 THE BOTTOM LINE Additionally, the differences between viruses, worms, and trojans are discussed. Finally, this section of Lesson 9 outlines a couple of common attacks and vulnerabilities found • EAP on networks. • Two-factor authentication • Multifactor authentication First, you need to answer the following questions: “What security threats does my company • Single sign-on have to combat?” and “Are there security threats that are common to the entire network?” After an Attack Explain common threats, 5.4 Next, you need to look at the unique threats that exist for your company or for specific por- Has Occurred vulnerabilities, and mitigation CERTIFICATION READY tions of your company.
It is important to realize that different companies in different lines of techniques. What are some common business have different priorities and needs when it comes to network security. This fact leads • Mitigation techniques: security threats to a different companies to take different measures in addressing threats that they consider specific network? What are some to their situation. The most important thing is that a company is looking at security threats • Training and awareness ways to mitigate those • Patch management and trying to address them.
As long as a company is at least aware of the specific threats out threats? • Incident response there to their own line of business, and are taking steps to address them, they are on the right 5. As the saying goes, “knowing is half the battle.” Network Tools that Can Be Used for Good or Bad Too often, companies—especially smaller ones—do not even think about these things. A com- pany that is not thinking about security issues is already at great risk and vulnerable to attack from outside groups or individuals. However, this issue is not limited to companies or busi- nesses; it is also a problem in our homes as well.
In fact, many small-time hackers (sometimes called script kiddies) actually actively target home computers. As the very first sentence of this KEY TERMS lesson said, any computer connected to any type of network is vulnerable to being attacked.