Network and Infrastructure Security Flashcards
6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Network and Infrastructure Security flashcards as text
Which of the following BEST reduces the risk of unauthorized wireless network access?
Answer: Using WPA3 with strong pre-shared keys and 802.1X authentication
WPA3 with 802.1X provides enterprise-grade authentication and strong encryption, making unauthorized access significantly harder.
When auditing a VPN implementation, an IS auditor should FIRST verify that:
Answer: Strong encryption algorithms and multi-factor authentication are enforced
Strong encryption and MFA are the foundational controls that protect VPN tunnels from interception and unauthorized access.
A penetration test differs from a vulnerability assessment primarily because a penetration test:
Answer: Actively attempts to exploit discovered vulnerabilities
Penetration testing goes beyond identifying vulnerabilities by actually attempting to exploit them to determine real-world impact.
Which firewall rule principle states that anything not explicitly permitted should be denied?
Answer: Default deny (implicit deny)
An implicit deny rule drops all traffic not explicitly allowed, minimizing exposure to unknown or unauthorized connections.
An IS auditor reviewing network diagrams notices that production and development environments share the same network segment. The MAIN risk is:
Answer: Potential for development activity to compromise production systems
Mixing production and development on the same segment can allow vulnerabilities or misconfigurations in dev to impact live systems.
Which of the following is the BEST control for preventing DNS spoofing attacks?
Answer: Implementing DNSSEC to cryptographically sign DNS records
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify authenticity and reject forged responses.