Network Security Architecture Flashcards
7 cards from real ISSAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security Architecture flashcards as text
Which network security architecture principle involves placing systems in separate security zones to limit the blast radius of a breach?
Answer: Network segmentation
Network segmentation divides a network into isolated zones so that a compromise in one zone cannot directly spread to others, limiting the breach's blast radius.
In a traditional three-tier network architecture, what is the primary security purpose of a DMZ (Demilitarized Zone)?
Answer: To isolate publicly accessible services from the internal network
The DMZ hosts publicly accessible services (e.g., web servers) while isolating them from the internal network, so external threats cannot directly reach internal resources.
A security architect is designing a Zero Trust network. Which of the following BEST describes the core tenet of Zero Trust?
Answer: Never trust, always verify — regardless of network location
Zero Trust operates on 'never trust, always verify,' requiring continuous authentication and authorization for every request regardless of where it originates.
Where should an Intrusion Detection System (IDS) sensor be placed to detect attacks targeting a public-facing web server in a DMZ?
Answer: Between the external firewall and the DMZ
Placing an IDS sensor between the external firewall and the DMZ allows it to inspect inbound traffic destined for DMZ services before it reaches those servers.
Which firewall deployment model inspects traffic based on the state of network connections and is considered more secure than simple packet filtering?
Answer: Stateful inspection firewall
A stateful inspection firewall tracks the state of active connections and uses this context to enforce policy, blocking packets that don't belong to a known legitimate session.
An enterprise wants to enforce consistent security policies for network access by verifying endpoint posture before granting connectivity. Which technology BEST supports this requirement?
Answer: Network Access Control (NAC)
Network Access Control (NAC) evaluates the security posture of endpoints (patch level, antivirus status, etc.) before permitting them to connect to network segments.
Which VPN architecture model routes all remote user traffic — including internet-bound traffic — through the corporate network for inspection?
Answer: Full tunneling
Full tunneling directs all remote user traffic through the corporate VPN gateway, allowing the enterprise to inspect and control all traffic including internet browsing.