← All CISSP Flashcard Decks

Communication and Network Security Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Communication and Network Security flashcards as text
  1. Which firewall architecture places a screened subnet (DMZ) between two firewalls to isolate public-facing servers?

    Answer: Screened subnet (dual-firewall DMZ) architecture

    The screened subnet architecture uses two firewalls creating a DMZ between them, isolating public services from the internal network even if the outer firewall is compromised.

  2. An IDS generates an alert for a known attack signature, but investigation reveals no actual attack occurred. This scenario is BEST described as:

    Answer: False positive

    A false positive occurs when an IDS alerts on benign activity that matches an attack signature, incorrectly indicating an attack took place.

  3. What is the MAIN security purpose of implementing Private VLANs (PVLANs)?

    Answer: Isolate hosts within the same VLAN from communicating directly with each other

    PVLANs use isolated, community, and promiscuous port types to restrict lateral communication between hosts sharing the same IP subnet.

  4. Which wireless authentication protocol is considered the MOST secure option for enterprise WPA3 deployments?

    Answer: WPA3-Enterprise with 192-bit mode (CNSA Suite)

    WPA3-Enterprise in 192-bit mode uses CNSA Suite algorithms (GCMP-256, BIP-GMAC-256, ECDHE) providing the highest security for wireless enterprise authentication.

  5. A security architect needs to ensure that a cloud-hosted application's API traffic is protected from volumetric DDoS attacks. Which solution is MOST appropriate?

    Answer: Use a cloud-based DDoS scrubbing service or CDN with DDoS mitigation

    Cloud-based DDoS scrubbing services absorb and filter volumetric attacks upstream, before traffic reaches the application, providing scalable mitigation beyond on-premises capacity.

  6. Which protocol vulnerability does the POODLE attack exploit?

    Answer: SSL 3.0 CBC padding oracle

    POODLE (Padding Oracle On Downgraded Legacy Encryption) exploits a padding oracle vulnerability in SSL 3.0's CBC mode encryption.

  7. When implementing IPsec in tunnel mode between two VPN gateways, which part of the original packet is encrypted?

    Answer: The entire original IP packet (header + payload)

    In IPsec tunnel mode, the entire original IP packet (header and payload) is encapsulated and encrypted within a new outer IP packet.