Communication and Network Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Communication and Network Security flashcards as text
Which protocol is used by network devices to dynamically assign IP addresses and provide configuration parameters to hosts?
Answer: DHCP
DHCP (Dynamic Host Configuration Protocol) dynamically assigns IP addresses, subnet masks, default gateways, and DNS server addresses to network clients.
A company discovers that an attacker exploited a switch to access traffic on a VLAN they should not have access to by sending specially crafted 802.1Q frames. This attack is known as:
Answer: VLAN hopping (double tagging)
VLAN hopping via double tagging embeds two 802.1Q tags so traffic crosses VLAN boundaries when the outer tag is stripped by the first switch.
Which network security concept ensures that all traffic, including internal east-west traffic, is inspected and no implicit trust is granted based on network location?
Answer: Zero Trust Network Access (ZTNA)
Zero Trust Network Access operates on the principle of 'never trust, always verify,' requiring authentication and authorization for all traffic regardless of source location.
What is the MAIN difference between a stateful packet inspection (SPI) firewall and a stateless packet filter?
Answer: SPI firewalls track connection state and context; packet filters evaluate each packet in isolation
Stateful inspection firewalls maintain a connection state table to evaluate packets in the context of their TCP/UDP session, while packet filters assess each packet independently.
Which Bluetooth attack allows an attacker to send unsolicited messages to a discoverable Bluetooth device without pairing?
Answer: Bluejacking
Bluejacking sends unsolicited messages (typically via vCard or messages) to nearby discoverable Bluetooth devices without requiring authentication or pairing.
An organization implements a proxy server that terminates client SSL sessions, inspects decrypted content, then re-encrypts and forwards traffic. This is BEST described as:
Answer: SSL/TLS inspection (man-in-the-middle proxy)
SSL/TLS inspection proxies act as a controlled man-in-the-middle, decrypting traffic for content inspection then re-encrypting to the destination server.
Which network protocol allows multiple physical WAN links to be combined into a single logical channel for increased bandwidth and redundancy?
Answer: Link Aggregation Control Protocol (LACP / 802.3ad)
LACP (802.3ad) negotiates link aggregation between devices, bundling multiple physical links into a single logical interface for both throughput and redundancy.