If you can't map an attack to its layer, you can't defend against it. Is a DDoS attack Layer 4 or Layer 7? Is ARP Poisoning Layer 2 or Layer 3? In this video, Sec Guy breaks down the OSI Model vs. TCP/IP, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) in Zero Trust, and shows you how to stop VLAN Hopping attacks.
🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥
\[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
\[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
\[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
\[ ] Domain 3.1: Secure Network Architecture (OSI Model, TCP/IP, VLANs)
\[ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP)
CISSP
\[ ] Domain 4: Communication & Network Security (OSI Layers & Secure Design)
\[ ] Domain 3: Security Architecture (Zero Trust Principles)
CISM
\[ ] Domain 3: Information Security Program (Network Infrastructure Security)
CRISC
\[ ] Domain 2: IT Risk Assessment (Network Vulnerabilities & Architecture Risks)
CCSP
\[ ] Domain 3: Cloud Infrastructure Security (Virtual Networking & VLANs)
SecurityX (CompTIA)
\[ ] Domain 1.0: Security Architecture (Network Segmentation & Zero Trust)
GIAC GSEC (SANS)
\[ ] Network Security Essentials: OSI, TCP/IP, & Defense in Depth
AWS CSS (Certified Security – Specialty)
\[ ] Domain 2: Infrastructure Security (VPC Design, Direct Connect vs. VPN)
Pentest+ (CompTIA)
\[ ] Domain 3: Attacks and Exploits (VLAN Hopping & ARP Poisoning)
CEH (Certified Ethical Hacker)
\[ ] Domain 3: Scanning Networks (Mapping Attacks to OSI Layers)
SecAI+
\[ ] AI Security: AI-Driven Network Segmentation & Anomaly Detection
\[Timestamps]
0:00 - Intro: The Battlefield of Architecture
0:36 - The OSI Model (7 Layers): "Please Do Not Throw Sausage Pizza Away"
1:01 - The TCP/IP Model (4 Layers): "All The Internet Needs"
1:25 - Mapping Attacks: DDoS (L7) vs. ARP Poisoning (L2)
1:50 - Hybrid Cloud: Site-to-Site VPN vs. Direct Connect
2:40 - The Death of the Flat Network: VLANs & 802.1Q
2:58 - Zero Trust Brain: Policy Decision Point (PDP) vs. Enforcement Point (PEP)
3:33 - Attack Vector: VLAN Hopping & Auto-Trunking
4:00 - Defense: Deception Technology (Honeynets)
4:16 - The Future: AI-Driven Dynamic Segmentation
4:52 - Summary: Segment Ruthlessly
5:08 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=i-jwtB3puxY