โ† All CISSP Flashcard Decks

Communication and Network Security Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Communication and Network Security flashcards as text
  1. Which protocol provides hop-by-hop encryption for MPLS VPN traffic between provider edge routers?

    Answer: MACsec (802.1AE)

    MACsec (802.1AE) operates at Layer 2 and provides hop-by-hop encryption between directly connected devices such as MPLS PE routers.

  2. A security analyst observes that a web application firewall is generating excessive false positives for legitimate API calls. Which tuning approach is BEST?

    Answer: Create allowlist rules for known-good API endpoints and tighten base signatures

    Creating allowlist rules for known-good API patterns while refining base signatures reduces false positives without eliminating protection.

  3. Which network architecture principle is BEST demonstrated by placing database servers in a separate VLAN accessible only from the application tier?

    Answer: Network segmentation

    Placing database servers in an isolated VLAN with restricted inter-tier access is a direct application of network segmentation.

  4. An organization uses 802.1X for wired network access control. Which component authenticates the end-user credentials?

    Answer: Authentication Server (RADIUS)

    In 802.1X, the Authentication Server (typically RADIUS) validates supplicant credentials; the authenticator (switch) enforces the decision.

  5. What is the PRIMARY purpose of a network tap versus a SPAN port for security monitoring?

    Answer: Taps provide passive, out-of-band full-duplex capture without affecting production traffic

    Network taps passively copy all traffic on a link out-of-band without introducing latency or risking dropped packets, unlike SPAN ports which share switch resources.

  6. Which DNS security mechanism cryptographically signs DNS records to prevent cache poisoning attacks?

    Answer: DNSSEC

    DNSSEC uses digital signatures on DNS resource records to allow resolvers to verify data authenticity and integrity, directly countering cache poisoning.

  7. During a network forensic investigation, an analyst discovers TCP sessions with SYN packets but no corresponding SYN-ACK replies across many source IPs. This MOST likely indicates:

    Answer: A distributed denial-of-service SYN flood attack

    Numerous SYN packets from many sources with no SYN-ACK responses is the classic signature of a SYN flood DDoS attack exhausting the target's connection table.