ISC2 CISSP Microsegmentation Wireless SDN VPC And Network Observability Practice Test
4 Communication and Network Security • 26 original questions
This CISSP practice test focuses on microsegmentation wireless sdn vpc and network observability through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a risk workshop for the remote access service, the team identifies Content distribution networks (CDN) as the deciding issue. The security architect is expected to address the control objective without granting broader privilege than the business need requires. What is the MOST appropriate course of action? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) without granting broader privilege than the business need requires.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) without granting broader privilege than the business need requires.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
A control owner at Consolidated Messenger proposes a quick technical fix for Software-defined networking, SD-WAN, APIs, and network functions virtualization in the customer identity platform. The security operations manager must address the control objective without creating a new single point of failure. What should happen FIRST? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
D: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization without creating a new single point of failure.
Learning point: Protect the SDN control plane and APIs with strong authentication, least privilege, change control, and monitoring. Centralized programmable control can become a high-impact target if its APIs or control plane are compromised.
Proseware Labs is standardizing security across several business units. The data analytics lake raises a question about Virtual Private Cloud (VPC). The business continuity lead needs to address the control objective while ensuring that emergency access cannot become permanent access. Which action provides the BEST governance and security outcome? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while ensuring that emergency access cannot become permanent access.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while ensuring that emergency access cannot become permanent access.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
During a network segmentation redesign, Southridge Media asks the privacy and compliance lead to address Network observability, traffic shaping, capacity management, and fault handling for its branch-office network. The requirement is to address the control objective while allowing independent verification of the control outcome. What should the organization do FIRST? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Network observability provides the evidence needed to detect failures and security deviations. It directly addresses Network observability, traffic shaping, capacity management, and fault handling while allowing independent verification of the control outcome.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
D: Network observability provides the evidence needed to detect failures and security deviations. It directly addresses Network observability, traffic shaping, capacity management, and fault handling while allowing independent verification of the control outcome.
Learning point: Collect flow and device telemetry, establish baselines, and alert on capacity, fault, and policy anomalies. Network observability provides the evidence needed to detect failures and security deviations.
Adventure Works is revising controls for its industrial control network. A review highlights Logical segmentation including VLANs, VPNs, VRFs, and virtual domains. The security architect must address the control objective while accounting for third-party and lifecycle dependencies. Which action is the BEST next step? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains while accounting for third-party and lifecycle dependencies.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
C: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains while accounting for third-party and lifecycle dependencies.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
An auditor asks VanArsdel Energy to demonstrate how it handles Micro-segmentation with distributed controls and zero trust in the research data repository. The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. Which response is MOST appropriate? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while maintaining the organization’s stated risk appetite.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
D: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while maintaining the organization’s stated risk appetite.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
After a business change, Northwind Health discovers that Edge networks, ingress/egress, and peering is not handled consistently for the payment processing service. The business continuity lead needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which recommendation BEST addresses the issue? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while meeting the business objective with the least unnecessary operational complexity.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
Coho Insurance is preparing a security decision for the software delivery pipeline. The decision involves Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which option BEST reflects CISSP-level security practice? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
B: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while keeping the control sustainable for normal operations.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
During a risk workshop for the AI-assisted customer service platform, the team identifies Cellular/mobile networks including 4G and 5G as the deciding issue. The security architect is expected to address the control objective while ensuring the decision can be repeated consistently across business units. What is the MOST appropriate course of action? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G while ensuring the decision can be repeated consistently across business units.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
B: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G while ensuring the decision can be repeated consistently across business units.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
A control owner at Blue Yonder Airlines proposes a quick technical fix for Content distribution networks (CDN) in the global collaboration platform. The security operations manager must address the control objective while preserving clear accountability and audit evidence. What should happen FIRST? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) while preserving clear accountability and audit evidence.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) while preserving clear accountability and audit evidence.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
City Power is standardizing security across several business units. The e-commerce application raises a question about Software-defined networking, SD-WAN, APIs, and network functions virtualization. The business continuity lead needs to address the control objective while protecting sensitive data throughout the change. Which action provides the BEST governance and security outcome? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization while protecting sensitive data throughout the change.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
D: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization while protecting sensitive data throughout the change.
Learning point: Protect the SDN control plane and APIs with strong authentication, least privilege, change control, and monitoring. Centralized programmable control can become a high-impact target if its APIs or control plane are compromised.
During a data-governance workshop, Tailspin Logistics asks the privacy and compliance lead to address Virtual Private Cloud (VPC) for its clinical records environment. The requirement is to address the control objective while preserving availability of the critical business service. What should the organization do FIRST? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while preserving availability of the critical business service.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
Alpine Sports is revising controls for its remote access service. A review highlights Logical segmentation including VLANs, VPNs, VRFs, and virtual domains. The security architect must address the control objective without replacing governance with a technology-only shortcut. Which action is the BEST next step? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains without replacing governance with a technology-only shortcut.
Option review:
A: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains without replacing governance with a technology-only shortcut.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
An auditor asks Fabrikam Manufacturing to demonstrate how it handles Micro-segmentation with distributed controls and zero trust in the customer identity platform. The security operations manager must address the control objective while keeping the process defensible to auditors and business owners. Which response is MOST appropriate? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while keeping the process defensible to auditors and business owners.
Option review:
A: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while keeping the process defensible to auditors and business owners.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
After a business change, Trey Research discovers that Edge networks, ingress/egress, and peering is not handled consistently for the data analytics lake. The business continuity lead needs to address the control objective while minimizing irreversible action until facts and authority are established. Which recommendation BEST addresses the issue? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while minimizing irreversible action until facts and authority are established.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
Margie Travel is preparing a security decision for the branch-office network. The decision involves Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. Which option BEST reflects CISSP-level security practice? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
D: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while preserving evidence needed for later review.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
During a risk workshop for the industrial control network, the team identifies Cellular/mobile networks including 4G and 5G as the deciding issue. The security architect is expected to address the control objective without granting broader privilege than the business need requires. What is the MOST appropriate course of action? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G without granting broader privilege than the business need requires.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
C: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G without granting broader privilege than the business need requires.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
A control owner at Bellows University proposes a quick technical fix for Content distribution networks (CDN) in the research data repository. The security operations manager must address the control objective without creating a new single point of failure. What should happen FIRST? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) without creating a new single point of failure.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Content distribution networks (CDN) without creating a new single point of failure.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Content distribution networks (CDN) in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
Litware Services is standardizing security across several business units. The payment processing service raises a question about Software-defined networking, SD-WAN, APIs, and network functions virtualization. The business continuity lead needs to address the control objective while ensuring that emergency access cannot become permanent access. Which action provides the BEST governance and security outcome? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization while ensuring that emergency access cannot become permanent access.
Option review:
A: Centralized programmable control can become a high-impact target if its APIs or control plane are compromised. It directly addresses Software-defined networking, SD-WAN, APIs, and network functions virtualization while ensuring that emergency access cannot become permanent access.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Software-defined networking, SD-WAN, APIs, and network functions virtualization in this scenario.
Learning point: Protect the SDN control plane and APIs with strong authentication, least privilege, change control, and monitoring. Centralized programmable control can become a high-impact target if its APIs or control plane are compromised.
During a regulatory readiness assessment, Humongous Insurance asks the privacy and compliance lead to address Virtual Private Cloud (VPC) for its software delivery pipeline. The requirement is to address the control objective while allowing independent verification of the control outcome. What should the organization do FIRST? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while allowing independent verification of the control outcome.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Virtual Private Cloud (VPC) while allowing independent verification of the control outcome.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Virtual Private Cloud (VPC) in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
Woodgrove Bank is revising controls for its AI-assisted customer service platform. A review highlights Network observability, traffic shaping, capacity management, and fault handling. The security architect must address the control objective while accounting for third-party and lifecycle dependencies. Which action is the BEST next step? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Network observability provides the evidence needed to detect failures and security deviations. It directly addresses Network observability, traffic shaping, capacity management, and fault handling while accounting for third-party and lifecycle dependencies.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
C: Network observability provides the evidence needed to detect failures and security deviations. It directly addresses Network observability, traffic shaping, capacity management, and fault handling while accounting for third-party and lifecycle dependencies.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Network observability, traffic shaping, capacity management, and fault handling in this scenario.
Learning point: Collect flow and device telemetry, establish baselines, and alert on capacity, fault, and policy anomalies. Network observability provides the evidence needed to detect failures and security deviations.
An auditor asks Relecloud Systems to demonstrate how it handles Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in the global collaboration platform. The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. Which response is MOST appropriate? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains while maintaining the organization’s stated risk appetite.
Option review:
A: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Logical segmentation including VLANs, VPNs, VRFs, and virtual domains while maintaining the organization’s stated risk appetite.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Logical segmentation including VLANs, VPNs, VRFs, and virtual domains in this scenario.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
After a business change, Contoso Financial discovers that Micro-segmentation with distributed controls and zero trust is not handled consistently for the e-commerce application. The business continuity lead needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which recommendation BEST addresses the issue? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Micro-segmentation with distributed controls and zero trust in this scenario.
D: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Micro-segmentation with distributed controls and zero trust while meeting the business objective with the least unnecessary operational complexity.
Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.
Lucerne Publishing is preparing a security decision for the clinical records environment. The decision involves Edge networks, ingress/egress, and peering. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. Which option BEST reflects CISSP-level security practice? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while keeping the control sustainable for normal operations.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Edge networks, ingress/egress, and peering while keeping the control sustainable for normal operations.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Edge networks, ingress/egress, and peering in this scenario.
Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.
During a risk workshop for the remote access service, the team identifies Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite as the deciding issue. The security architect is expected to address the control objective while ensuring the decision can be repeated consistently across business units. What is the MOST appropriate course of action? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while ensuring the decision can be repeated consistently across business units.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite in this scenario.
D: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Wireless networks including Bluetooth, Wi-Fi, Zigbee, and satellite while ensuring the decision can be repeated consistently across business units.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
A control owner at Fourth Coffee proposes a quick technical fix for Cellular/mobile networks including 4G and 5G in the customer identity platform. The security operations manager must address the control objective while preserving clear accountability and audit evidence. What should happen FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G while preserving clear accountability and audit evidence.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Cellular/mobile networks including 4G and 5G in this scenario.
D: Wireless and mobile networks extend the attack surface beyond wired physical boundaries. It directly addresses Cellular/mobile networks including 4G and 5G while preserving clear accountability and audit evidence.
Learning point: Use strong authentication and encryption, isolate untrusted wireless access, and manage radio-specific risks and rogue devices. Wireless and mobile networks extend the attack surface beyond wired physical boundaries.
Popular posts
Recent Posts
