ISC2 CISSP Network Models Protocols Performance And Core Segmentation Practice Test

 

4 Communication and Network Security • 26 original questions

This CISSP practice test focuses on network models protocols performance and core segmentation through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

After a business change, Fabrikam Manufacturing discovers that Converged protocols including iSCSI and VoIP is not handled consistently for the software delivery pipeline. The application security architect needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The environment spans 2 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP while preserving availability of the critical business service.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP while preserving availability of the critical business service.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 2

Trey Research is preparing a security decision for the AI-assisted customer service platform. The decision involves Transport architecture and data/control/management planes. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The environment spans 7 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes without replacing governance with a technology-only shortcut.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes without replacing governance with a technology-only shortcut.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 3

During a risk workshop for the global collaboration platform, the team identifies Bandwidth, latency, jitter, throughput, and signal-to-noise ratio as the deciding issue. The security governance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The environment spans 5 network segments and carries both east-west and north-south traffic.

  1. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  2. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: A

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while keeping the process defensible to auditors and business owners.

Option review:

A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while keeping the process defensible to auditors and business owners.

B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 4

A control owner at Wide World Importers proposes a quick technical fix for North-south and east-west traffic flows in the e-commerce application. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The environment spans 4 network segments and carries both east-west and north-south traffic.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic.

Correct answer: D

Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while minimizing irreversible action until facts and authority are established.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

D: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while minimizing irreversible action until facts and authority are established.

Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.

Question 5

Bellows University is standardizing security across several business units. The clinical records environment raises a question about Physical segmentation including out-of-band and air-gapped networks. The application security architect needs to address the control objective while preserving evidence needed for later review. Which action provides the BEST governance and security outcome? The environment spans 3 network segments and carries both east-west and north-south traffic.

  1. Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: A

Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Physical segmentation including out-of-band and air-gapped networks while preserving evidence needed for later review.

Option review:

A: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Physical segmentation including out-of-band and air-gapped networks while preserving evidence needed for later review.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.

Question 6

During a secure software initiative, Litware Services asks the incident response manager to address OSI and TCP/IP models for its remote access service. The requirement is to address the control objective without granting broader privilege than the business need requires. What should the organization do FIRST? The environment spans 2 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models without granting broader privilege than the business need requires.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models without granting broader privilege than the business need requires.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 7

Humongous Insurance is revising controls for its customer identity platform. A review highlights IPv4 and IPv6 including unicast, broadcast, multicast, and anycast. The security governance lead must address the control objective without creating a new single point of failure. Which action is the BEST next step? The environment spans 7 network segments and carries both east-west and north-south traffic.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.

Correct answer: D

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast without creating a new single point of failure.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast without creating a new single point of failure.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 8

An auditor asks Woodgrove Bank to demonstrate how it handles Secure protocols including IPsec, SSH, SSL, and TLS in the data analytics lake. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which response is MOST appropriate? The environment spans 5 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while ensuring that emergency access cannot become permanent access.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

B: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while ensuring that emergency access cannot become permanent access.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

Learning point: Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites. Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound.

Question 9

After a business change, Relecloud Systems discovers that Implications of multilayer protocols is not handled consistently for the branch-office network. The application security architect needs to address the control objective while allowing independent verification of the control outcome. Which recommendation BEST addresses the issue? The environment spans 4 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: C

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while allowing independent verification of the control outcome.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while allowing independent verification of the control outcome.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 10

Contoso Financial is preparing a security decision for the industrial control network. The decision involves Converged protocols including iSCSI and VoIP. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. Which option BEST reflects CISSP-level security practice? The environment spans 3 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP while accounting for third-party and lifecycle dependencies.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP while accounting for third-party and lifecycle dependencies.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 11

During a risk workshop for the research data repository, the team identifies Transport architecture and data/control/management planes as the deciding issue. The security governance lead is expected to address the control objective while maintaining the organization’s stated risk appetite. What is the MOST appropriate course of action? The environment spans 2 network segments and carries both east-west and north-south traffic.

  1. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  2. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: A

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes while maintaining the organization’s stated risk appetite.

Option review:

A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes while maintaining the organization’s stated risk appetite.

B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 12

A control owner at Lamna Healthcare proposes a quick technical fix for Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in the payment processing service. The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. What should happen FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.

Correct answer: D

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while meeting the business objective with the least unnecessary operational complexity.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 13

Fourth Coffee is standardizing security across several business units. The software delivery pipeline raises a question about North-south and east-west traffic flows. The application security architect needs to address the control objective while keeping the control sustainable for normal operations. Which action provides the BEST governance and security outcome? The environment spans 5 network segments and carries both east-west and north-south traffic.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: B

Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

B: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while keeping the control sustainable for normal operations.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.

Question 14

During a third-party onboarding review, Consolidated Messenger asks the incident response manager to address OSI and TCP/IP models for its AI-assisted customer service platform. The requirement is to address the control objective while ensuring the decision can be repeated consistently across business units. What should the organization do FIRST? The environment spans 4 network segments and carries both east-west and north-south traffic.

  1. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: A

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models while ensuring the decision can be repeated consistently across business units.

Option review:

A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models while ensuring the decision can be repeated consistently across business units.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 15

Proseware Labs is revising controls for its global collaboration platform. A review highlights IPv4 and IPv6 including unicast, broadcast, multicast, and anycast. The security governance lead must address the control objective while preserving clear accountability and audit evidence. Which action is the BEST next step? The environment spans 3 network segments and carries both east-west and north-south traffic.

  1. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  2. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast while preserving clear accountability and audit evidence.

Option review:

A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast while preserving clear accountability and audit evidence.

B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 16

An auditor asks Southridge Media to demonstrate how it handles Secure protocols including IPsec, SSH, SSL, and TLS in the e-commerce application. The IAM architect must address the control objective while protecting sensitive data throughout the change. Which response is MOST appropriate? The environment spans 2 network segments and carries both east-west and north-south traffic.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: C

Why: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

C: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while protecting sensitive data throughout the change.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

Learning point: Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites. Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound.

Question 17

After a business change, Adventure Works discovers that Implications of multilayer protocols is not handled consistently for the clinical records environment. The application security architect needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The environment spans 7 network segments and carries both east-west and north-south traffic.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  4. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while preserving availability of the critical business service.

C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 18

VanArsdel Energy is preparing a security decision for the remote access service. The decision involves Converged protocols including iSCSI and VoIP. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The environment spans 6 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP without replacing governance with a technology-only shortcut.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Converged protocols including iSCSI and VoIP without replacing governance with a technology-only shortcut.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Converged protocols including iSCSI and VoIP in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 19

During a risk workshop for the customer identity platform, the team identifies Transport architecture and data/control/management planes as the deciding issue. The security governance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The environment spans 4 network segments and carries both east-west and north-south traffic.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: B

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes while keeping the process defensible to auditors and business owners.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Transport architecture and data/control/management planes while keeping the process defensible to auditors and business owners.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transport architecture and data/control/management planes in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 20

A control owner at Coho Insurance proposes a quick technical fix for Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in the data analytics lake. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The environment spans 3 network segments and carries both east-west and north-south traffic.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  4. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.

Correct answer: D

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while minimizing irreversible action until facts and authority are established.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Bandwidth, latency, jitter, throughput, and signal-to-noise ratio in this scenario.

D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Bandwidth, latency, jitter, throughput, and signal-to-noise ratio while minimizing irreversible action until facts and authority are established.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 21

  1. Datum Analytics is standardizing security across several business units. The branch-office network raises a question about North-south and east-west traffic flows. The application security architect needs to address the control objective while preserving evidence needed for later review. Which action provides the BEST governance and security outcome? The environment spans 2 network segments and carries both east-west and north-south traffic.
  2. Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  5. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while preserving evidence needed for later review.

Option review:

A: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses North-south and east-west traffic flows while preserving evidence needed for later review.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address North-south and east-west traffic flows in this scenario.

Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.

Question 22

During a acquisition integration, Blue Yonder Airlines asks the incident response manager to address Physical segmentation including out-of-band and air-gapped networks for its industrial control network. The requirement is to address the control objective without granting broader privilege than the business need requires. What should the organization do FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.

  1. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: C

Why: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Physical segmentation including out-of-band and air-gapped networks without granting broader privilege than the business need requires.

Option review:

A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

C: Segmentation reduces blast radius only when allowed paths are explicit and observable. It directly addresses Physical segmentation including out-of-band and air-gapped networks without granting broader privilege than the business need requires.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Physical segmentation including out-of-band and air-gapped networks in this scenario.

Learning point: Segment by trust boundary and workload need, explicitly control permitted flows, and monitor east-west as well as north-south traffic. Segmentation reduces blast radius only when allowed paths are explicit and observable.

Question 23

City Power is revising controls for its research data repository. A review highlights OSI and TCP/IP models. The security governance lead must address the control objective without creating a new single point of failure. Which action is the BEST next step? The environment spans 6 network segments and carries both east-west and north-south traffic.

  1. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  4. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.

Correct answer: A

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models without creating a new single point of failure.

Option review:

A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses OSI and TCP/IP models without creating a new single point of failure.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address OSI and TCP/IP models in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 24

An auditor asks Tailspin Logistics to demonstrate how it handles IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in the payment processing service. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which response is MOST appropriate? The environment spans 4 network segments and carries both east-west and north-south traffic.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  4. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.

Correct answer: D

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address IPv4 and IPv6 including unicast, broadcast, multicast, and anycast in this scenario.

D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses IPv4 and IPv6 including unicast, broadcast, multicast, and anycast while ensuring that emergency access cannot become permanent access.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Question 25

After a business change, Alpine Sports discovers that Secure protocols including IPsec, SSH, SSL, and TLS is not handled consistently for the software delivery pipeline. The application security architect needs to address the control objective while allowing independent verification of the control outcome. Which recommendation BEST addresses the issue? The environment spans 3 network segments and carries both east-west and north-south traffic.

  1. Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while allowing independent verification of the control outcome.

Option review:

A: Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound. It directly addresses Secure protocols including IPsec, SSH, SSL, and TLS while allowing independent verification of the control outcome.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Secure protocols including IPsec, SSH, SSL, and TLS in this scenario.

Learning point: Use the appropriate modern authenticated encryption protocol and disable obsolete protocol versions and weak cipher suites. Secure protocols protect channel confidentiality and integrity only when endpoint authentication and configuration are sound.

Question 26

Fabrikam Manufacturing is preparing a security decision for the AI-assisted customer service platform. The decision involves Implications of multilayer protocols. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. Which option BEST reflects CISSP-level security practice? The environment spans 2 network segments and carries both east-west and north-south traffic.

  1. Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring.
  2. Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components.
  3. Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while accounting for third-party and lifecycle dependencies.

Option review:

A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. It directly addresses Implications of multilayer protocols while accounting for third-party and lifecycle dependencies.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Implications of multilayer protocols in this scenario.

Learning point: Design the network around trust boundaries and traffic flows, use secure protocols and segmentation, and maintain observability appropriate to the architecture. Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter.

Popular posts

img