Network Security Architecture Flashcards
7 cards from real ISSAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security Architecture flashcards as text
Micro-segmentation in a data center environment is MOST effective at controlling which type of traffic?
Answer: East-west traffic between workloads within the data center
Micro-segmentation applies granular policies to east-west (lateral) traffic between workloads inside the data center, preventing lateral movement by attackers.
A security architect is leveraging Software-Defined Networking (SDN) for security. Which capability of SDN BEST enhances the security posture?
Answer: Enables centralized, programmable policy enforcement across the network
SDN's centralized control plane allows security policies to be programmatically defined and consistently enforced across all network devices from a single controller.
Which DNS security extension provides cryptographic authentication of DNS responses to prevent cache poisoning attacks?
Answer: DNSSEC
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify the authenticity and integrity of DNS responses and prevent cache poisoning.
An architect needs to protect BGP routing infrastructure from route hijacking. Which security control BEST addresses this threat?
Answer: Implementing Resource Public Key Infrastructure (RPKI) with Route Origin Authorization
RPKI with Route Origin Authorization (ROA) cryptographically validates that BGP route announcements originate from authorized Autonomous Systems, mitigating route hijacking.
Which network security monitoring approach captures full packet data for retrospective analysis of security incidents?
Answer: Full packet capture (PCAP)
Full packet capture (PCAP) records the complete contents of network packets, enabling security analysts to reconstruct sessions and perform detailed forensic analysis after an incident.
In a secure network architecture, which technique is used to prevent a compromised VLAN from sending tagged frames to unauthorized VLANs?
Answer: VLAN hopping prevention via disabling DTP and setting native VLANs
Disabling Dynamic Trunking Protocol (DTP) and configuring a dedicated, unused native VLAN prevents double-tagging and switch spoofing attacks that enable VLAN hopping.
Which network architecture design pattern uses a bastion host to provide controlled administrative access to systems in a protected network segment?
Answer: Jump server (jump box)
A jump server (jump box) is a hardened, monitored bastion host that administrators must connect through to reach systems in restricted segments, providing an audited single point of entry.