โ† All CISA Flashcard Decks

Network and Infrastructure Security Flashcards

6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Network and Infrastructure Security flashcards as text
  1. Which network security device inspects packet headers and filters traffic based on predefined rules without examining packet content?

    Answer: Packet-filtering firewall

    A packet-filtering firewall examines IP headers, ports, and protocols but does not inspect the actual content of packets.

  2. A CISA auditor reviewing network segmentation should PRIMARILY verify that:

    Answer: Critical systems are isolated in separate network zones

    Proper network segmentation places critical systems in isolated zones to limit the blast radius of a breach.

  3. Which protocol provides encrypted remote administration of network devices and is preferred over Telnet?

    Answer: SSH

    SSH (Secure Shell) encrypts the entire session, whereas Telnet transmits credentials and data in plaintext.

  4. An Intrusion Prevention System (IPS) differs from an IDS primarily because an IPS can:

    Answer: Actively block or drop malicious traffic in real time

    An IPS sits inline with traffic and can actively block threats, whereas an IDS only monitors and alerts.

  5. During a network audit, an IS auditor finds that SNMP v1 is still in use. The PRIMARY concern is:

    Answer: SNMP v1 community strings are transmitted in plaintext

    SNMP v1 community strings (essentially passwords) are sent in cleartext, making them vulnerable to interception.

  6. A DMZ (Demilitarized Zone) is BEST described as:

    Answer: A network zone between the internet and the internal network that hosts public-facing services

    A DMZ provides a buffer zone that exposes public services (e.g., web servers) while shielding the internal network.