Courseiva

CISSP · topic practice

Communication and Network Security practice questions

Domain 4 covers securing data in motion across OSI layers: secure protocols, network architecture, and transmission media. CISSP questions present attack scenarios (rogue APs, on-path interception, weak authentication) and ask you to select the correct protocol, control, or countermeasure. Expect to compare IPSec, TLS, SSH, DNSSEC, and VPN types by their cryptographic guarantees and failure modes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Communication and Network Security

What the exam tests

What to know about Communication and Network Security

Map each scenario to the correct protocol and its security property: DNSSEC signs DNS records, SFTP/SCP ride SSH, IPSec or TLS-based VPNs replace PPTP/MS-CHAPv2, and rogue-AP interception calls for stronger wireless authentication and monitoring. The key is matching the control to the exact attack.

Selecting secure protocols such as IPSec, TLS, SSH, DNSSEC, and S/MIME for specific requirements

Distinguishing network attacks: rogue access points, evil twin, on-path interception, and spoofing

Choosing VPN technologies (IPSec, TLS-based, SSH tunnels) by authentication and encryption support

Applying OSI-layer controls: segmentation, VLANs, NAC, wireless encryption, and secure routing

Watch out for

Common Communication and Network Security exam traps

  • ▸Confusing DNSSEC, which signs DNS data for authenticity and integrity, with DNS-over-HTTPS, which only encrypts the query in transit.
  • ▸Assuming SSH alone transfers files; SFTP or SCP must be named, since plain SSH is a remote shell, not a file-transfer protocol.
  • ▸Picking PPTP or MS-CHAPv2 for legacy VPN compatibility despite known dictionary-attack weaknesses; IPSec or TLS-based VPNs are correct.

Practice set

Communication and Network Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full wireless explanation →

An organization is deploying a wireless network with WPA3-Enterprise. Which THREE of the following are features or improvements of WPA3 compared to WPA2? (Select THREE.)

Which of the following is a key feature of TLS 1.3 that enhances security compared to earlier versions?

An organization is reviewing its use of SSH for remote administration. Which TWO features of SSH should be disabled or carefully managed to reduce security risks? (Select two.)

Question 4hardmultiple choice
Read the full wireless explanation →

A company is migrating from WPA2 to WPA3 to enhance wireless security. Which of the following cryptographic changes does WPA3 introduce compared to WPA2?

A security architect is designing a network for a healthcare organization that must comply with HIPAA. The network will use a Demilitarized Zone (DMZ) to host public-facing web servers. The architect must ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which TWO of the following controls are MOST effective to achieve this? (Choose two.)

A security analyst observes a network attack where an attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. This attack occurs at which layer of the OSI model?

Question 7hardmultiple choice
Read the full VPN explanation →

An organization is deploying a VPN solution for remote employees. The security team requires a modern protocol with perfect forward secrecy, uses elliptic curve cryptography, and is known for its efficient, minimal codebase. Which VPN protocol should they choose?

A security engineer is configuring a firewall that makes decisions based on source/destination IP addresses and port numbers without tracking the state of connections. Which type of firewall is this?

During a security assessment, a penetration tester sends TCP SYN packets to various ports on a target server. Based on the responses, the tester determines which ports are open. This technique is commonly used at which OSI layer?

An organization wants to secure email communications by providing encryption and digital signatures. They require a solution that uses a web of trust model rather than a hierarchical PKI. Which protocol should they implement?

A network administrator is configuring SNMPv3 for monitoring network devices. The organization requires both authentication and encryption of SNMP traffic. Which combination of protocols should be used to meet this requirement?

Question 12easymultiple choice
Read the full wireless explanation →

Which wireless security protocol replaces the pre-shared key (PSK) authentication with Simultaneous Authentication of Equals (SAE) to provide stronger security and forward secrecy?

Question 13mediummultiple choice
Read the full wireless explanation →

A security analyst discovers an attack where an attacker sets up a rogue wireless access point with a legitimate SSID to trick users into connecting. Once connected, the attacker captures credentials. This type of attack is known as:

An organization is implementing network segmentation. They need to place publicly accessible servers (e.g., web and email) in a separate network that is isolated from the internal LAN but still allows controlled access from the internet. Which architecture should they use?

Question 15hardmultiple choice
Read the full DNS explanation →

A company deploys DNSSEC to protect its DNS infrastructure. Which cryptographic operation does DNSSEC primarily use to ensure the authenticity and integrity of DNS data?

Which of the following is a key feature of TLS 1.3 that enhances security compared to earlier versions?

A security architect is designing a zero-trust network. Which principle is fundamental to a zero-trust architecture (ZTA) such as BeyondCorp?

Question 18hardmultiple choice
Read the full VPN explanation →

A network engineer is configuring an IPsec VPN in tunnel mode. Which IPsec protocol provides both authentication and encryption of the entire IP packet?

Which type of firewall is capable of inspecting application-layer data, performing SSL decryption, and integrating intrusion prevention capabilities?

A company uses SSH for remote administration. To enhance security, they want to implement public-key authentication. Which statement about SSH public-key authentication is true?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Communication and Network Security sessions

Start a Communication and Network Security only practice session

Every question in these sessions is drawn from the Communication and Network Security domain — nothing else.

Related practice questions

Related CISSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISSP exam test about Communication and Network Security?
Map each scenario to the correct protocol and its security property: DNSSEC signs DNS records, SFTP/SCP ride SSH, IPSec or TLS-based VPNs replace PPTP/MS-CHAPv2, and rogue-AP interception calls for stronger wireless authentication and monitoring. The key is matching the control to the exact attack.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Communication and Network Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Communication and Network Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISSP topics?
Use the topic links above to move to related areas, or go back to the CISSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISSP exam covers. They are not copied from any real exam or dump site.