CSS Network Security & Architecture Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CSS Network Security & Architecture flashcards as text
Which network design principle places security controls at multiple layers to ensure no single point of failure?
Answer: Defense in depth
Defense in depth layers multiple independent security controls so that a failure in one does not compromise the entire system.
What is the purpose of network flow data (NetFlow) in security monitoring?
Answer: Provides metadata about network conversations for traffic analysis and anomaly detection
NetFlow records metadata such as source/destination IPs, ports, and byte counts, enabling visibility into network behavior without capturing full packet content.
Which attack floods a target server with half-open TCP connections to exhaust its resources?
Answer: SYN flood
A SYN flood sends massive numbers of TCP SYN packets without completing the handshake, consuming server connection table resources.
What is the security benefit of using software-defined networking (SDN) in enterprise environments?
Answer: Centralized control plane enables consistent policy enforcement and rapid response to threats
SDN's centralized control plane allows security policies to be applied uniformly across the network and updated dynamically in response to threats.
Which protocol secures management plane communications to network devices by encrypting CLI sessions?
Answer: SSH (Secure Shell)
SSH encrypts command-line sessions to network devices, replacing the plaintext Telnet protocol for secure device management.
What does network micro-segmentation achieve that traditional perimeter security cannot?
Answer: Limits lateral movement by enforcing granular policies between individual workloads
Micro-segmentation creates fine-grained security zones around individual workloads, blocking attacker lateral movement even after perimeter breach.