Communication and Network Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Communication and Network Security flashcards as text
Which protocol provides hop-by-hop encryption for MPLS VPN traffic between provider edge routers?
Answer: MACsec (802.1AE)
MACsec (802.1AE) operates at Layer 2 and provides hop-by-hop encryption between directly connected devices such as MPLS PE routers.
A security analyst observes that a web application firewall is generating excessive false positives for legitimate API calls. Which tuning approach is BEST?
Answer: Create allowlist rules for known-good API endpoints and tighten base signatures
Creating allowlist rules for known-good API patterns while refining base signatures reduces false positives without eliminating protection.
Which network architecture principle is BEST demonstrated by placing database servers in a separate VLAN accessible only from the application tier?
Answer: Network segmentation
Placing database servers in an isolated VLAN with restricted inter-tier access is a direct application of network segmentation.
An organization uses 802.1X for wired network access control. Which component authenticates the end-user credentials?
Answer: Authentication Server (RADIUS)
In 802.1X, the Authentication Server (typically RADIUS) validates supplicant credentials; the authenticator (switch) enforces the decision.
What is the PRIMARY purpose of a network tap versus a SPAN port for security monitoring?
Answer: Taps provide passive, out-of-band full-duplex capture without affecting production traffic
Network taps passively copy all traffic on a link out-of-band without introducing latency or risking dropped packets, unlike SPAN ports which share switch resources.
Which DNS security mechanism cryptographically signs DNS records to prevent cache poisoning attacks?
Answer: DNSSEC
DNSSEC uses digital signatures on DNS resource records to allow resolvers to verify data authenticity and integrity, directly countering cache poisoning.
During a network forensic investigation, an analyst discovers TCP sessions with SYN packets but no corresponding SYN-ACK replies across many source IPs. This MOST likely indicates:
Answer: A distributed denial-of-service SYN flood attack
Numerous SYN packets from many sources with no SYN-ACK responses is the classic signature of a SYN flood DDoS attack exhausting the target's connection table.