new 640-802 emerging drag and drop questions
1.Firewall isolate two or more physical network of a system (or a combination of many systems); Firewall with centralized management, implementation, monitoring the characteristics of security policy; general firewall can be open (unTrust, Internet), risk (DMZ, WAN) the domain with the private, trusted (Trust, LAN) domain segregated; be regarded as the network firewall, goalkeeper, but they can provide protection is very limited. The biggest problem is that the firewall can not check the contents of packets passed.
IDS / IPS (Intrusion Detection and Prevention System) intrusion detection systems can help identify at an early stage attacks, provides organizations with rapid analysis of information security incidents with more response time, and the deployment of defense mechanisms to guard against further attacks. To check the contents of the packet, enterprises must deploy in the security by adding intrusion detection mechanisms.
Anti-Spyware is only being installed / had installed spy software role; to the file system and registry files for protection.
Anti-Virus not been able to focus on control-spyware can detect a small fraction of known spyware (spy tens of thousands of kinds of software); Basically, the signature detection method has its limitations; anti-virus tools, only protect a single desktop system, and use a limited subscription-based update method.
2.
LMI -provides starts messages between DTE and DCE device
PVC -the most common type of virtor urcult
DLCI -identifies the virtval connection between the DTE the switch
DTE -a router is this type of device


