A defensive control is a measure that prevents, detects or limits harm to a system. You should be able to name a control, say what it checks or does, and say what it protects against. This lesson looks at two: a firewall and two-factor authentication.
It continues from spotting phishing and sits within the internet security module.
What does a firewall do?
A firewall sits between a network and the internet. Every packet of data is compared with rules, such as which ports or addresses are allowed.
Packets that match an allowed rule pass. Packets that break a rule are blocked and can be logged.
A firewall protects against unauthorised incoming connections. It does not read your mind: if you allow a harmful program to run, the firewall may not know.
What is two-factor authentication (2FA)?
Authentication proves who you are. Factors come in kinds:
- something you know: password, PIN
- something you have: phone, security token
- something you are: fingerprint, face
2FA needs two different kinds. A password plus a code sent to your registered phone is two factors. A password plus a second password is not, because both are things you know.
Worked example
A school’s student portal currently needs only a username and password. The school adds 2FA. Explain how this improves security.
Step 1, the existing weakness: if a password is revealed, for example by a phishing message, anyone with it can log in.
Step 2, the change: after the password, the portal sends a six-digit code to the student’s registered phone, valid for a short time.
Step 3, the effect: a person who has the password but not the phone cannot complete the login.
Step 4, the limit: if the student is tricked into typing the code into a fake page, the control is bypassed. User awareness is still needed.
A full-mark style answer: “2FA requires a second type of evidence, so a stolen password alone is not enough to access the account.”
The mistake to watch for
Mistaken answer: “A firewall stops viruses.”
The student gave a result without saying what a firewall does.
A firewall examines network traffic against rules and blocks traffic that breaks them. Detecting and removing malware files is the job of anti-malware software. Match each control to its action: firewall checks traffic, anti-malware scans files, updates fix known weaknesses, 2FA adds a second proof.
Check yourself
1. Is “a password and a security question” two-factor authentication? Explain.
Show answer
No. Both are things you know, so they are the same kind of factor. Two-factor needs two different kinds, for example a password plus a code sent to a phone.
2. Describe what a firewall does with a packet that breaks its rules.
Show answer
It blocks the packet so it does not reach the network or computer, and it may log the attempt for the administrator to review.
3. Give one control that protects against known weaknesses in software, and say what it does.
Show answer
Software updates (patches). They fix known weaknesses in a program so they can no longer be misused. Keeping the operating system and browser updated is a common answer.
Where does this lead next?
Bring the whole module together with the mixed practice set, and recap how users reach sites with the browser-server lesson. Use the mistake log and retest queue for weak points. For the next topic, see automation and emerging systems.
If you want a teacher to check your written security answers against what a marker looks for, that is part of online one-to-one Computer Science tuition.