Courseiva
easyMultiple Select

CISSP Practice Question: Which three are network-layer security controls…

Which three are network-layer security controls in a defense-in-depth strategy? (Choose THREE.)

⚠ Common exam trap

Candidates often confuse network-level controls with host-level or data-level controls. While antivirus and encryption at rest are critical security measures, they protect endpoints and stored data respectively, rather than securing the network transit layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access control lists (ACLs)

Access control lists (ACLs) (B) are correct because they are enforced on routers and layer-3 switches to filter packets by source/destination IP address, protocol, and port, directly controlling traffic at the network layer. Firewall (D) is correct because firewalls operate at layers 3 and 4 (and beyond), inspecting and permitting or denying packets based on IP addresses, ports, and connection state, which is a core network-layer defense-in-depth control. Intrusion Detection System (IDS) (E) is correct because network-based IDS sensors monitor layer-3 traffic for malicious patterns and anomalies, providing detection at the network layer. Antivirus (A) is not a network-layer control; it is a host-based endpoint control that scans files and processes at the application/host level. Data encryption at rest (C) is not a network-layer control; it protects stored data on disks or databases at the data/presentation layer rather than filtering network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Antivirus

    Why it's wrong here

    Antivirus software primarily functions as a host-based security control, operating at the endpoint level (e.g., workstations, servers) to detect, prevent, and remove malicious software. It inspects files, processes, and system memory for known signatures or behavioral anomalies, which places its operational scope firmly within the application and operating system layers of a specific host, rather than the network layer where traffic routing and forwarding decisions occur.

  • ✓

    Access control lists (ACLs)

    Why this is correct

    Access Control Lists (ACLs) are a fundamental network layer security control, typically configured on routers and firewalls, to filter incoming and outgoing network traffic. They operate by examining packet headers, specifically source and destination IP addresses (Network Layer, Layer 3) and often source and destination port numbers (Transport Layer, Layer 4). This granular control allows administrators to permit or deny traffic flows based on predefined rules, directly impacting network connectivity and resource access.

  • ✗

    Data encryption at rest

    Why it's wrong here

    Data encryption at rest is a crucial security measure designed to protect information stored on persistent storage devices, such as hard drives, solid-state drives, or databases. This control encrypts data when it is not actively being used or transmitted, safeguarding it against unauthorized access if the storage medium is compromised. Its operation is entirely independent of network traffic flow or packet processing, placing it firmly within the data and storage layers, not the network layer.

  • ✓

    Firewall

    Why this is correct

    A firewall is a primary network layer security control that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. While traditional packet-filtering firewalls operate at the network and transport layers by inspecting IP addresses and port numbers, more advanced stateful and application-layer firewalls extend this capability, but their core function remains traffic control at the network boundary. This strategic placement allows them to enforce access rules and block unauthorized communications effectively.

  • ✓

    Intrusion Detection System (IDS)

    Why this is correct

    An Intrusion Detection System (IDS) is a critical network layer security control designed to monitor network traffic for suspicious activity and known threats, alerting administrators when potential intrusions are detected. Network-based IDSs (NIDS) analyze packet headers and payloads in real-time as they traverse the network, comparing them against signature databases of known attacks or behavioral baselines. While it doesn't actively block traffic like a firewall, its role in identifying malicious network-borne activity is central to network security.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Go deeper

Related to this question

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.