โ† All ISSAP Flashcard Decks

Network Security Architecture Flashcards

7 cards from real ISSAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Architecture flashcards as text
  1. An organization is transitioning to IPv6. Which security consideration is MOST important for a security architect to address during the transition?

    Answer: Dual-stack environments may expose IPv6 interfaces that bypass existing IPv4 security controls

    In dual-stack environments, systems expose both IPv4 and IPv6 interfaces; existing security controls configured only for IPv4 may not inspect IPv6 traffic, creating blind spots.

  2. Which design approach BEST improves network resilience by eliminating single points of failure at the network layer?

    Answer: Implementing redundant links with dynamic routing protocols such as OSPF or BGP

    Redundant links combined with dynamic routing protocols allow traffic to automatically reroute around failures, eliminating single points of failure and improving network resilience.

  3. An ISSAP candidate is reviewing a network design that uses out-of-band (OOB) management. What is the PRIMARY security benefit of OOB management?

    Answer: It isolates management traffic from production traffic, preserving access during attacks or outages

    Out-of-band management uses a separate network path for administrative access, ensuring that management connectivity is preserved even when production network paths are congested or under attack.

  4. When designing network security architecture, which concept ensures that only the minimum necessary network traffic is permitted between zones by default?

    Answer: Default deny (implicit deny) policy

    A default deny (implicit deny) policy blocks all traffic not explicitly permitted by firewall rules, ensuring attackers cannot exploit undefined or forgotten rule gaps.

  5. A security architect must ensure that sensitive network traffic between data centers is protected in transit. Which solution provides both confidentiality and integrity for this traffic?

    Answer: IPsec tunnel mode between data center gateways

    IPsec tunnel mode encrypts the entire original IP packet and provides both confidentiality and integrity verification, protecting data in transit between data centers.

  6. Which network security architecture model uses software-defined perimeters to make infrastructure invisible to unauthorized users before authentication occurs?

    Answer: Software-Defined Perimeter (SDP) / Zero Trust Network Access (ZTNA)

    SDP/ZTNA makes network resources invisible (dark) to unauthenticated users and only establishes encrypted connections to specific resources after identity and device posture are verified.

  7. When conducting a network security architecture review, an architect evaluates trust zones. Which factor is MOST critical when defining trust zone boundaries?

    Answer: The sensitivity of data and systems within the zone and the risk of interconnection

    Trust zone boundaries should be defined by the sensitivity of assets and data contained within and the risk posed by allowing traffic between zones, ensuring high-value assets are maximally isolated.

Network Security Architecture Flashcards โ€” ISSAP Study Cards with Answers