16 questions

Communication and Network Security

A router forwards packets between subnets by examining destination IP addresses. At which OSI layer does this forwarding decision take place?

  • a.Session layer (Layer 5)
  • b.Data link layer (Layer 2)
  • c.Network layer (Layer 3)✓
  • d.Transport layer (Layer 4)

In the OSI reference model (ISO/IEC 7498-1) routing and logical addressing belong to the network layer, which is where IP operates. The data link layer handles frames and local hardware addressing within one link, the transport layer handles end-to-end delivery using ports, and the session layer manages dialogues between applications.

Communication and Network Security

A simple packet filter allows inbound traffic only to TCP port 443. Which OSI layer's information is the filter using when it checks the port number?

  • a.Transport layer✓
  • b.Presentation layer
  • c.Physical layer
  • d.Data link layer

TCP and UDP port numbers are transport-layer fields in the OSI model (ISO/IEC 7498-1) and in the TCP/IP model, so a filter that decides on ports is reading transport-layer headers. The physical layer carries bits, the presentation layer handles data representation, and the data link layer uses hardware addresses, none of which contain port numbers.

Communication and Network Security

Two sites need an IPsec connection that keeps the payload secret from eavesdroppers. Why is the Authentication Header (AH) alone insufficient?

  • a.AH gives integrity but not confidentiality✓
  • b.AH works only in tunnel mode between gateways
  • c.AH encrypts only the packet header, not the payload
  • d.AH cannot be used with IPv6 networks

RFC 4301 states that AH offers integrity and data origin authentication, while ESP offers the same services and also confidentiality, so ESP is needed to keep the payload secret. RFC 4301 applies AH to both IPv4 and IPv6, supports AH in both transport and tunnel modes, and AH performs no encryption at all.

Communication and Network Security

An organization connects two branch offices through their security gateways and wants the entire original IP packet, including its inner addresses, protected across the internet. Which IPsec mode fits?

  • a.Promiscuous mode
  • b.Tunnel mode✓
  • c.Passive mode
  • d.Transport mode

RFC 4301 explains that in transport mode AH and ESP protect mainly the next-layer protocol data, while in tunnel mode they are applied to tunneled IP packets, encapsulating the whole original packet behind a new outer header; this is the normal gateway-to-gateway case. Passive and promiscuous modes are not IPsec modes.

Communication and Network Security

An attacker records encrypted TLS 1.3 sessions today and later steals the server's long-term private key. Why can the attacker still not decrypt the recorded sessions?

  • a.TLS 1.3 servers rotate certificates every session
  • b.TLS 1.3 key exchanges provide forward secrecy✓
  • c.TLS 1.3 encrypts recordings with a hash
  • d.TLS 1.3 removed support for symmetric encryption

RFC 8446 states that static RSA and Diffie-Hellman cipher suites were removed and that all public-key key-exchange mechanisms in TLS 1.3 now provide forward secrecy, so session keys come from ephemeral exchanges that the long-term key cannot reconstruct. Hashes do not encrypt, certificates are not replaced per session, and TLS 1.3 still protects records with symmetric AEAD ciphers.

Communication and Network Security

Network engineers still administer core switches over Telnet. What is the most appropriate replacement, and why?

  • a.SNMPv1, because it is designed for device management
  • b.FTP, because it offers a separate control channel
  • c.HTTP, because browsers are available on every workstation
  • d.SSH, because it encrypts and authenticates the session✓

RFC 4251 describes SSH as a protocol for secure remote login and other secure network services over an insecure network, protecting credentials and commands that Telnet sends in the clear. FTP, SNMPv1 community strings and plain HTTP all transmit credentials without encryption, so each repeats Telnet's weakness.

Communication and Network Security

A DNS provider assigns the same IPv6 address to resolvers in several regions so that each query reaches the closest one. Which address type is being used?

  • a.Multicast
  • b.Link-local unicast
  • c.Broadcast
  • d.Anycast✓

RFC 4291 defines an anycast address as identifying a set of interfaces, with a packet delivered to one of them, the 'nearest' according to routing. A multicast packet goes to all interfaces in the set, IPv6 has no broadcast addresses, and a link-local unicast address identifies a single interface on one link.

Communication and Network Security

A security team is updating a network monitoring rule set for an IPv6-only segment. Which IPv4 addressing function will not exist there, because IPv6 replaces it with multicast?

  • a.Anycast
  • b.Multicast
  • c.Broadcast✓
  • d.Unicast

RFC 4291 states that there are no broadcast addresses in IPv6, their function being superseded by multicast addresses. Unicast, anycast and multicast are all defined IPv6 address types, multicast being the one that takes over broadcast's role.

Communication and Network Security

A company deploys DNSSEC for its public zones. Which protection does DNSSEC add?

  • a.Encryption of zone transfers
  • b.Confidentiality of DNS queries
  • c.Origin authentication and data integrity✓
  • d.Protection against denial of service

RFC 4033 describes DNSSEC as providing data origin authentication and data integrity for DNS data and states that the extensions do not provide confidentiality; it also notes DNSSEC does not protect against denial of service. Encrypting queries or zone transfers requires other mechanisms.

Communication and Network Security

An attacker who compromised one web server is moving laterally to database servers in the same data center. Which approach most directly limits this server-to-server traffic?

  • a.Micro-segmentation of east-west traffic✓
  • b.Higher bandwidth between the data center racks
  • c.A larger perimeter firewall on the internet link
  • d.A content delivery network in front of the site

The ISC2 outline lists micro-segmentation (overlays, distributed firewalls, zero trust) and distinguishes east-west from north-south traffic; NIST SP 800-207 likewise notes that no implicit trust based on network location forces attackers to compromise each resource separately. A perimeter firewall and a CDN act on north-south traffic entering from the internet, and more bandwidth does nothing to restrict flows.

Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Communication and Network Security

A storage team runs iSCSI across the general-purpose corporate network. Which step addresses the main security concern with this converged protocol?

  • a.Isolate storage traffic and authenticate initiators✓
  • b.Disable logging on the storage array to reduce load
  • c.Increase the MTU so each frame holds more data
  • d.Move the storage traffic to Telnet sessions

iSCSI carries SCSI block storage commands over TCP/IP, so storage becomes reachable wherever IP reaches; RFC 7143 security considerations describe authentication such as CHAP and IPsec for protecting sessions, and isolating storage traffic reduces exposure. Telnet adds no protection, MTU tuning is a performance change, and disabling logging removes visibility.

Communication and Network Security

A switch port keeps a new laptop off the network until the laptop's credentials are checked by a RADIUS server. In IEEE 802.1X terms, what role does the switch play?

  • a.Authentication server
  • b.Supplicant
  • c.Certificate authority
  • d.Authenticator✓

IEEE 802.1X port-based network access control defines three roles: the supplicant (the laptop requesting access), the authenticator (the switch or access point that controls the port and relays the exchange), and the authentication server (typically RADIUS) that validates credentials. A certificate authority issues certificates and is not an 802.1X role.

Communication and Network Security

An organization adopts software-defined networking. Which architectural change creates a new high-value target that must be protected?

  • a.Packet forwarding moves into the application layer
  • b.Physical cabling is replaced with wireless links
  • c.Every switch runs its own routing protocol
  • d.Control-plane logic moves to a central controller✓

RFC 7426 describes SDN as separating the forwarding plane from the control plane, with control logic centralized in controllers that program network devices; compromising the controller can reconfigure the whole network. Independent per-switch routing is the traditional model SDN changes, SDN does not require wireless links, and forwarding stays in network devices.

Communication and Network Security

Users of a VoIP service report choppy audio even though average latency is low and no packets are lost. Which performance metric most likely explains this?

  • a.Bandwidth
  • b.Throughput
  • c.Jitter✓
  • d.Signal-to-noise ratio

RFC 3393 defines IP packet delay variation, commonly called jitter, as the variation in delay between packets; real-time voice is sensitive to uneven arrival even when average delay is fine. Throughput and bandwidth describe how much data can move, and signal-to-noise ratio describes physical link quality that would normally show up as loss or errors.

Communication and Network Security

Remote staff connect over a VPN whose client sends only traffic for internal resources through the tunnel, while web browsing goes straight to the internet. What risk does NIST SP 800-46 Rev. 2 associate with this configuration?

  • a.Internal traffic is sent without encryption
  • b.The VPN gateway must decrypt all internet traffic
  • c.Users cannot reach internal resources at all
  • d.Traffic outside the tunnel is not inspected or protected✓

SP 800-46 Rev. 2 explains that split tunneling protects internal-resource traffic but prevents the organization from examining much of the teleworker's traffic and protecting its confidentiality and integrity, and it can bridge trusted and untrusted networks. Internal traffic is still tunneled, the gateway sees less traffic rather than all of it, and internal access still works.

Communication and Network Security

An organization wants its edge routers to stop outbound packets whose source addresses do not belong to its own address space. What does this control achieve?

  • a.It encrypts all outbound traffic at the edge
  • b.It balances load across two internet providers
  • c.It stops hosts inside from sending forged-source traffic✓
  • d.It blocks inbound scans from the internet

RFC 2827 (BCP 38) recommends filtering so that traffic leaving a network carries only source addresses legitimately assigned to it, which stops hosts inside from launching attacks with forged source addresses. Filtering does not encrypt anything, inbound scanning is addressed by ingress rules, and load balancing is a routing function.

Report