Courseiva

CISSP · domain

Communication and Network Security

Domain 4 covers securing data in motion across OSI layers: secure protocols, network architecture, and transmission media. CISSP questions present attack scenarios (rogue APs, on-path interception, weak authentication) and ask you to select the correct protocol, control, or countermeasure. Expect to compare IPSec, TLS, SSH, DNSSEC, and VPN types by their cryptographic guarantees and failure modes.

57 questions14 easy28 medium15 hard

Focused practice

Practice Communication and Network Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Communication and Network Security

Map each scenario to the correct protocol and its security property: DNSSEC signs DNS records, SFTP/SCP ride SSH, IPSec or TLS-based VPNs replace PPTP/MS-CHAPv2, and rogue-AP interception calls for stronger wireless authentication and monitoring. The key is matching the control to the exact attack.

Selecting secure protocols such as IPSec, TLS, SSH, DNSSEC, and S/MIME for specific requirements

Distinguishing network attacks: rogue access points, evil twin, on-path interception, and spoofing

Choosing VPN technologies (IPSec, TLS-based, SSH tunnels) by authentication and encryption support

Applying OSI-layer controls: segmentation, VLANs, NAC, wireless encryption, and secure routing

Watch out for

Common Communication and Network Security exam traps

  • ▸Confusing DNSSEC, which signs DNS data for authenticity and integrity, with DNS-over-HTTPS, which only encrypts the query in transit.
  • ▸Assuming SSH alone transfers files; SFTP or SCP must be named, since plain SSH is a remote shell, not a file-transfer protocol.
  • ▸Picking PPTP or MS-CHAPv2 for legacy VPN compatibility despite known dictionary-attack weaknesses; IPSec or TLS-based VPNs are correct.

Question index

All Communication and Network Security questions (57)

Click any question to see the full explanation, or start a practice session above.

1

During a penetration test, an ethical hacker sets up a rogue access point with the same SSID as the corporate network and broadcasts a stronger signal. Users inadvertently connect to the rogue AP, allowing the hacker to capture credentials. What is this attack called?

Hard
2

Which of the following is a secure protocol for transferring files that uses SSH for authentication and encryption?

Easy
3

An organization wants to secure email communications by providing encryption and digital signatures. They require a solution that uses a web of trust model rather than a hierarchical PKI. Which protocol should they implement?

Medium
4

A security engineer is configuring a firewall that makes decisions based on source/destination IP addresses and port numbers without tracking the state of connections. Which type of firewall is this?

Easy
5

An organization is implementing DNSSEC to protect against DNS spoofing attacks. Which of the following best describes the primary security function provided by DNSSEC?

Medium
6

A network administrator is configuring SNMPv3 for monitoring network devices. The organization requires both authentication and encryption of SNMP traffic. Which combination of protocols should be used to meet this requirement?

Hard
7

An organization is implementing network segmentation to enhance security. They create a DMZ to host public-facing servers and want to ensure that if a server is compromised, the attacker cannot pivot to the internal network. Which firewall placement best achieves this?

Medium
8

A security engineer is recommending a VPN protocol for remote access. The requirements are: strong encryption, perfect forward secrecy, use of elliptic curve cryptography, and minimal overhead. Which VPN protocol best meets these requirements?

Medium
9

An organization is deploying a VPN solution for remote employees. The security team requires a modern protocol with perfect forward secrecy, uses elliptic curve cryptography, and is known for its efficient, minimal codebase. Which VPN protocol should they choose?

Hard
10

A company wants to secure email communications for its employees. They need to ensure message confidentiality and integrity, and also verify the sender's identity. Which protocol uses a hierarchical public key infrastructure (PKI) for email encryption and signing?

Medium
11

A company wants to securely transfer files between systems over SSH. Which protocol should they use to leverage the existing SSH infrastructure and provide both authentication and encryption?

Medium
12

A security architect is designing a zero-trust network. Which principle is fundamental to a zero-trust architecture (ZTA) such as BeyondCorp?

Medium
13

A security analyst discovers an attack where an attacker sets up a rogue wireless access point with a legitimate SSID to trick users into connecting. Once connected, the attacker captures credentials. This type of attack is known as:

Medium
14

A network engineer is configuring an IPsec VPN in tunnel mode. Which IPsec protocol provides both authentication and encryption of the entire IP packet?

Hard
15

An organization is implementing network segmentation. They need to place publicly accessible servers (e.g., web and email) in a separate network that is isolated from the internal LAN but still allows controlled access from the internet. Which architecture should they use?

Medium
16

During a security assessment, a penetration tester successfully performs an ARP spoofing attack, redirecting traffic through their machine. This attack exploits which protocol vulnerability?

Hard
17

Which IPsec protocol provides both authentication and encryption of the packet payload, but does not encrypt the IP header?

Easy
18

A security administrator is evaluating secure file transfer protocols. Which THREE of the following protocols provide encryption for data in transit? (Select THREE.)

Hard
19

A financial services company needs to provide remote employees with access to internal applications. The security policy mandates that the solution must support granular access control based on user identity, integrate with the existing RADIUS server, and encrypt all traffic. The IT team is evaluating remote access technologies. Which of the following best meets these requirements?

Medium
20

A company is implementing TLS 1.3 to secure web communications. Which of the following features is unique to TLS 1.3 compared to earlier versions?

Medium
21

An incident responder is analyzing a network compromise that involved ICMP attacks. Which THREE types of ICMP attacks could have been used to disrupt network operations? (Select three.)

Medium
22

Which of the following is a key feature of TLS 1.3 that enhances security compared to earlier versions?

Easy
23

After a recent security audit, a network administrator discovers that an attacker has been intercepting traffic by associating with a legitimate access point's MAC address and broadcasting a stronger signal. Which type of attack has occurred?

Medium
24

A company is migrating from WPA2 to WPA3 to improve wireless security. Which THREE of the following are features of WPA3 compared to WPA2?

Medium
25

A security engineer is configuring SNMPv3 on network devices. The policy requires both authentication and encryption of SNMP messages. Which combination of protocols should be used to meet this requirement?

Hard
26

An attacker sends a flood of SYN packets to a server, consuming its resources and preventing legitimate connections. Which OSI layer is this attack targeting?

Easy
27

A security administrator is configuring SNMPv3 for network device monitoring. The requirement is to provide both authentication and encryption of SNMP traffic. Which combination of options should be used?

Medium
28

An organization is implementing DNSSEC to protect its DNS infrastructure. Which of the following best describes the primary security benefit of DNSSEC?

Hard
29

Which wireless security protocol replaces the pre-shared key (PSK) authentication with Simultaneous Authentication of Equals (SAE) to provide stronger security and forward secrecy?

Easy
30

During a security assessment, a consultant discovers that a legacy VPN solution uses MS-CHAPv2 for authentication and does not support IKE. The protocol is known to be vulnerable to dictionary attacks. Which VPN protocol is most likely being used?

Hard
31

A security team is reviewing network segmentation strategies. Which TWO of the following are benefits of using VLANs? (Select TWO.)

Medium
32

A security analyst observes a network attack where an attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. This attack occurs at which layer of the OSI model?

Medium
33

A network administrator is deploying a wireless network for a small business and wants to ensure strong security. Which of the following is the best choice for authentication in a WPA3 Personal network?

Medium
34

A network administrator is configuring a firewall that examines the source and destination IP addresses, port numbers, and protocol (TCP/UDP) of each packet without considering the state of the connection. Which type of firewall is being deployed?

Easy
35

During a penetration test, the tester successfully performs a VLAN hopping attack by sending packets with a specific tag. Which mitigation technique is most effective at preventing double-tagging VLAN hopping?

Hard
36

A security analyst is evaluating secure email protocols. Which TWO of the following provide both encryption and digital signing of email messages?

Easy
37

Which type of firewall can inspect the contents of application-layer traffic, such as HTTP requests, and block malicious payloads?

Medium
38

A security architect is designing a network segmentation strategy for a financial institution. Which TWO techniques are best suited for implementing micro-segmentation in a data center environment? (Select two.)

Medium
39

A security analyst notices that an attacker is sending forged ARP messages onto a local area network, linking the attacker's MAC address with the IP address of the default gateway. This allows the attacker to intercept traffic destined for the gateway. Which OSI layer is directly targeted by this attack?

Medium
40

A security architect is designing a zero trust network. Which principle is fundamental to a zero trust architecture?

Medium
41

A network administrator is reviewing the security of the company's VPN solution. They discover that the current VPN uses PPTP. Which TWO of the following are significant security weaknesses associated with PPTP?

Hard
42

An organization is migrating from WPA2 to WPA3 for its wireless network. Which improvement does WPA3 provide over WPA2?

Medium
43

During a security assessment, a penetration tester sends TCP SYN packets to various ports on a target server. Based on the responses, the tester determines which ports are open. This technique is commonly used at which OSI layer?

Medium
44

A security team is implementing a zero trust architecture. Which component is essential to enforce access decisions based on user identity, device posture, and context before granting access to resources?

Medium
45

A network administrator is configuring DNSSEC to protect against DNS spoofing. Which record type is used to provide cryptographic verification of DNS data origins?

Hard
46

A company uses SSH for remote administration. To enhance security, they want to implement public-key authentication. Which statement about SSH public-key authentication is true?

Medium
47

A security engineer is evaluating VPN protocols for a remote access solution. The requirements are: strong encryption with perfect forward secrecy, support for mutual authentication, and no reliance on pre-shared keys that could be brute-forced. Which protocol best meets these requirements?

Hard
48

Which TWO features are true of IPsec tunnel mode compared to transport mode? (Select two.)

Easy
49

A company is designing a network segmentation strategy to isolate a public-facing web server from the internal corporate network. Which of the following is the most appropriate architecture?

Medium
50

Which VPN technology operates at Layer 2 of the OSI model and is often used in combination with IPsec to provide encryption?

Easy
51

In IPsec, which protocol provides both authentication and encryption for the packet payload, but does not encrypt the IP header?

Easy
52

Which type of firewall is capable of inspecting application-layer data, performing SSL decryption, and integrating intrusion prevention capabilities?

Easy
53

A company deploys DNSSEC to protect its DNS infrastructure. Which cryptographic operation does DNSSEC primarily use to ensure the authenticity and integrity of DNS data?

Hard
54

A company is deploying a VPN solution for remote employees using SSL/TLS VPN. Which TWO security considerations are important when implementing this type of VPN? (Select two.)

Hard
55

Which type of firewall operates at Layer 7 and can inspect application payloads, such as blocking specific SQL commands or HTTP methods?

Easy
56

A security analyst is configuring a firewall to allow HTTP traffic (TCP port 80) from the internet to a web server in the DMZ. The firewall should also allow return traffic from the server back to the internet. Which type of firewall is best suited to handle this traffic while maintaining security?

Easy
57

A security analyst detects an attack where the attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. Which OSI layer is primarily targeted by this attack?

Medium

Frequently asked questions

What does the Communication and Network Security domain cover on the CISSP exam?
Map each scenario to the correct protocol and its security property: DNSSEC signs DNS records, SFTP/SCP ride SSH, IPSec or TLS-based VPNs replace PPTP/MS-CHAPv2, and rogue-AP interception calls for stronger wireless authentication and monitoring. The key is matching the control to the exact attack.
How many questions are in this domain?
This page lists all 57 Communication and Network Security questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Communication and Network Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp network security Practice Questions