easyMultiple Select
CISSP Practice Question: Which three are network-layer security controls…
Which three are network-layer security controls in a defense-in-depth strategy? (Choose THREE.)
⚠ Common exam trap
Candidates often confuse network-level controls with host-level or data-level controls. While antivirus and encryption at rest are critical security measures, they protect endpoints and stored data respectively, rather than securing the network transit layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access control lists (ACLs)
Access control lists (ACLs) (B) are correct because they are enforced on routers and layer-3 switches to filter packets by source/destination IP address, protocol, and port, directly controlling traffic at the network layer. Firewall (D) is correct because firewalls operate at layers 3 and 4 (and beyond), inspecting and permitting or denying packets based on IP addresses, ports, and connection state, which is a core network-layer defense-in-depth control. Intrusion Detection System (IDS) (E) is correct because network-based IDS sensors monitor layer-3 traffic for malicious patterns and anomalies, providing detection at the network layer. Antivirus (A) is not a network-layer control; it is a host-based endpoint control that scans files and processes at the application/host level. Data encryption at rest (C) is not a network-layer control; it protects stored data on disks or databases at the data/presentation layer rather than filtering network traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus
Why it's wrong here
Antivirus software primarily functions as a host-based security control, operating at the endpoint level (e.g., workstations, servers) to detect, prevent, and remove malicious software. It inspects files, processes, and system memory for known signatures or behavioral anomalies, which places its operational scope firmly within the application and operating system layers of a specific host, rather than the network layer where traffic routing and forwarding decisions occur.
- ✓
Access control lists (ACLs)
Why this is correct
Access Control Lists (ACLs) are a fundamental network layer security control, typically configured on routers and firewalls, to filter incoming and outgoing network traffic. They operate by examining packet headers, specifically source and destination IP addresses (Network Layer, Layer 3) and often source and destination port numbers (Transport Layer, Layer 4). This granular control allows administrators to permit or deny traffic flows based on predefined rules, directly impacting network connectivity and resource access.
- ✗
Data encryption at rest
Why it's wrong here
Data encryption at rest is a crucial security measure designed to protect information stored on persistent storage devices, such as hard drives, solid-state drives, or databases. This control encrypts data when it is not actively being used or transmitted, safeguarding it against unauthorized access if the storage medium is compromised. Its operation is entirely independent of network traffic flow or packet processing, placing it firmly within the data and storage layers, not the network layer.
- ✓
Firewall
Why this is correct
A firewall is a primary network layer security control that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. While traditional packet-filtering firewalls operate at the network and transport layers by inspecting IP addresses and port numbers, more advanced stateful and application-layer firewalls extend this capability, but their core function remains traffic control at the network boundary. This strategic placement allows them to enforce access rules and block unauthorized communications effectively.
- ✓
Intrusion Detection System (IDS)
Why this is correct
An Intrusion Detection System (IDS) is a critical network layer security control designed to monitor network traffic for suspicious activity and known threats, alerting administrators when potential intrusions are detected. Network-based IDSs (NIDS) analyze packet headers and payloads in real-time as they traverse the network, comparing them against signature databases of known attacks or behavioral baselines. While it doesn't actively block traffic like a firewall, its role in identifying malicious network-borne activity is central to network security.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Encryption at rest
Encryption at rest is the practice of securing stored data by converting it into an unreadable format using cryptographic algorithms, so that even if physical or digital access to the storage medium is obtained, the data remains confidential.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.