4.0 Communication and Network Security CISSP Practice Quiz
104 exam-style questions covering 13% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Network engineering at a regional bank is finalizing the segmentation design for a new core banking refresh. The engineering team asks for CISSP-level guidance on secure design principles in network architectures. Which approach is most appropriate?
- A. Segment the architecture by trust boundary, business function, and data sensitivity, then enforce traffic flows with routed controls and policy points
- B. Provision new partner VPN tunnels with no owner, no monitoring, and no review
- C. Skip monitoring on TLS-encrypted paths because the traffic is encrypted
- D. Allow overlapping IP address ranges across acquired entities and patch routing later
Network segmentation limits lateral movement and aligns network access with business and security requirements. This is the correct answer.
Operations at a regional utility is segmenting OT and IT networks following an industry-wide ICS warning. The security architect must make a communication and network security decision involving secure design principles in network architectures. What is the best recommendation?
- A. Separate management planes from production data planes and restrict administrative access through controlled jump hosts or privileged access paths
- B. Stand up site-to-site VPNs for partners without monitoring or ownership records
- C. Skip flow monitoring on encrypted paths because confidentiality is covered
- D. Tolerate overlapping subnets across acquired companies and reconcile later
Management interfaces are high-value targets and should be isolated and tightly monitored. This is the correct answer.
A federal agency is reviewing its network architecture against zero-trust principles ahead of a TIC 3.0 review. A security assurance review must address secure design principles in network architectures. What should the security professional recommend?
- A. Treat cloud-provider VPC networking as inherently secure with no customer review
- B. Use defense in depth with network, identity, endpoint, application, monitoring, and physical controls rather than relying on a single perimeter
- C. Build a single flat network so every system can reach every other system
- D. Use a single perimeter firewall as the entire network security architecture
Layered network security reduces dependence on one control and improves resilience when one layer fails. This is the correct answer.
A consumer fintech is hardening its API gateway and edge after a credential-stuffing wave. A network architecture review identifies a weakness in secure design principles in network architectures. Which action should be prioritized?
- A. Skip validating customer-side cloud network controls because the provider 'handles it'
- B. Use secure network architecture reviews to evaluate topology, trust boundaries, routing, remote access, and monitoring before deployment
- C. Avoid segmentation to make a single flat network for all systems
- D. Treat the perimeter firewall as the only network security control
Architecture review identifies design weaknesses before they become operational dependencies. This is the correct answer.
Network engineering at a multinational logistics provider is integrating two acquired carriers. Executives need a risk-based explanation for secure design principles in network architectures. Which response best aligns with secure network practice?
- A. Treat cloud network security as a provider-only responsibility
- B. Use secure access service edge patterns when distributed users need consistent security inspection for cloud and internet access
- C. Use a single flat L2 broadcast domain across the entire enterprise
- D. Rely on a single edge firewall as the entirety of network security
SASE can combine network access and security policy enforcement for dispersed users and services. This is the correct answer.
A children's hospital is redesigning its network to segregate clinical, biomedical, and administrative traffic. A proposed network design creates risk around secure design principles in network architectures. Which design change best addresses the concern?
- A. Add a new partner VPN as a permanent fixture with no review schedule
- B. Disable east-west monitoring on encrypted flows because they're 'protected'
- C. Design high availability with redundant paths, diverse providers, resilient routing, and tested failover for critical communications
- D. Use conflicting RFC1918 ranges between acquired networks and fix routing later
Network availability depends on eliminating avoidable single points of failure and proving failover behavior. This is the correct answer.
Network architecture at a research university is mapping flows ahead of a federally funded research project. The engineering team asks for CISSP-level guidance on secure design principles in network architectures. Which approach is most appropriate?
- A. Provision permanent partner VPNs with no owner or review process
- B. Disable network monitoring on encrypted segments because the traffic is encrypted
- C. Design cloud and hybrid connectivity by clarifying shared responsibility, routing, encryption, logging, and provider dependency risks
- D. Use the same address ranges in two merged networks and fix it later
Hybrid and cloud networking require explicit control ownership and visibility across environments. This is the correct answer.
A SaaS provider is integrating multi-region network controls for a new global tenant onboarding rollout. Executives need a risk-based explanation for secure design principles in network architectures. Which response best aligns with secure network practice?
- A. Assume the cloud provider's network is secure with no validation of customer scope
- B. Use one flat /16 so every device can reach every other device directly
- C. Rely on one internet firewall as the complete network security strategy
- D. Apply zero trust principles by continuously verifying identity, device posture, context, and authorization for network access
Zero trust reduces implicit trust based on location and supports secure access across distributed environments. This is the correct answer.
Key Terms in This Domain
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- ISO 27001: International standard for an information security management system (ISMS)
- CASB: Cloud Access Security Broker: policy enforcement for SaaS access
- HSM: Hardware Security Module: tamper-resistant key management device
- OSI Model: 7-layer reference: Physical, Data Link, Network, Transport, Session, Presentation, Application
- IPSec: Network-layer protocol suite for VPNs (AH, ESP, IKE)
- TLS: Transport Layer Security: encrypts application traffic
- VLAN: Logical L2 segmentation within a physical network
- VPN: Encrypted tunnel over a public network
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/communication-and-network-security/
<a href="https://quizbuffet.com/isc2-cissp/communication-and-network-security/">CISSP (ISC2) Communication and Network Security practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 2.0 Asset Security
- 3.0 Security Architecture and Engineering
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.