awesome-everything RU
↑ Back to the climb

Networking & Protocols

Network security: free-recall review

Crux Free-recall prompts across the network-security unit. Answer each in your own words first, then reveal the model answer and compare.
Your altitude — climbing toward senior
ZeroJuniorMiddleSenior
You are at senior altitude — in orbit
◷ 14 min

Retrieval beats re-reading. For each prompt, say or write a full answer from memory before you open the model answer — the effort of recall is what makes the unit stick.

Goal

Reconstruct the unit’s spine without looking back: why attack economics favor the attacker alone, how amplification and state-exhaustion work, where firewalls end and WAFs begin, what DNSSEC and RPKI each protect, and why defense in depth is non-negotiable.

Recall before you leave
  1. 01
    Why do DDoS attack economics favor the attacker only if you defend alone, and how does a CDN invert that?
  2. 02
    Explain amplification/reflection and why it is the attacker's economist choice.
  3. 03
    How do SYN cookies defeat a SYN flood, and what is the tradeoff?
  4. 04
    Where does a firewall stop being enough and a WAF begin, and why is neither sufficient alone?
  5. 05
    What does DNSSEC protect versus RPKI/ROV, and why is publishing a ROA without ROV enforcement only half a defense?
  6. 06
    Why is no single layer enough against DDoS, and what does a full defense-in-depth stack look like in order?
Recap

If you could reconstruct each answer from memory, you hold the unit’s spine: attack economics favor the lone defender, so you share infrastructure; amplification and SYN floods turn a cheap attacker into a flood you absorb rather than blocklist; firewalls and WAFs cover disjoint layers; DNSSEC and RPKI/ROV protect DNS responses and BGP routes respectively — each useless as a half-measure; and no single layer stops every vector, which is why defense in depth stacks anycast edge, L3/L4 filters, WAF, rate limits, mTLS, and adaptive concurrency, with humans on call for the rest.

Continue the climb ↑Network security: config and log reading
shortcuts expand
search
K
prev piece
k
next piece
j
cycle tier
t
this menu
?
sources3
expand
  1. 01
  2. 02
  3. 03

Trademarks belong to their respective owners. Editorial reference only.