Communication and Network Security
CISSP · 39 questions
- While troubleshooting a broken encrypted session between a city workstation and a cloud case portal, an engineer needs to reason about which networking layer typically provides confidentiality services for that session. Which approach best applies OSI/TCP-IP models?
- During IPv4/IPv6 dual-stack rollout, a city team treats anycast the same as local subnet broadcast for service discovery and opens overly broad multicast groups. What should the architect emphasize?
- Network staff still use cleartext Telnet to manage closet routers for a municipal campus. What is the most appropriate remediation?
- City VoIP phones and iSCSI storage traffic share the same congested campus links with no QoS and no segmentation. What risk assessment conclusion is most accurate?
- A city's microservices platform firewalled only north-south Internet edges while east-west service-to-service chatter remains unmonitored and unrestricted. What design correction is needed?
- County election systems require stronger isolation than general office IT, including management that does not ride the same production voting network. Which approach best matches that need?
- Finance servers and guest Wi-Fi clients currently share one flat VLAN in city hall. What logical segmentation approach should the architect apply?
- Incident responders trace lateral movement from a compromised lobby printer into the CAD network. Which network-security approach best limits that path going forward?
- A city Internet edge peers with two ISPs for the municipal data center. Engineers discover inbound routes accept almost any prefix and there is no scrubbing or rate-limiting plan for volumetric floods. Which design change best hardens ingress and egress at this peering edge?
- A parks department still runs city Wi-Fi with outdated cipher suites, while field crews also deploy Bluetooth beacons and Zigbee sensors for irrigation telemetry. Which approach best strengthens wireless security across these municipal links?
- Building inspectors tether GIS map updates over personal 5G hotspots with no mobile device management and no split-tunnel policy for city applications. Which control set best addresses the cellular and mobile network risk?
- A county publishes emergency-alert pages through a content delivery network. Architects worry that the origin is reachable directly and that poisoned cache objects could mislead the public. Which CDN design practice best addresses those concerns?
- A municipality replaces branch routers with SD-WAN and API-driven SDN controllers. A mis-pushed policy briefly black-holed traffic and later opened an unintended path between guest and finance VLANs. Which security awareness should guide ongoing SD-WAN and SDN operations?
- Municipal permitting and payment workloads are moving into a virtual private cloud. Planners need subnetting, gateways, and isolation that match sensitivity. Which VPC design principle is most appropriate?
- A city’s SOC cannot tell whether large outbound transfers from a records office are backups or exfiltration because no flow telemetry is collected on core egress. Which design addition best improves detection and fault awareness?
- Attackers induce abnormal jitter and latency on the WAN path that carries VoIP for the city’s 911 call-taking centers. Which statement best reflects how bandwidth, latency, jitter, and throughput should inform secure and resilient design?
- On the city’s core switches, management SSH and SNMP share the same VLANs and paths used by ordinary user data, with no ACL restricting who can reach the management plane. Which change best improves transport architecture security?
- A county portal still offers SSL and early TLS for 'compatibility,' including connections to citizen payment pages. Which protocol decision aligns with modern secure design?
- Fire stations need resilient connectivity back to the city’s public-safety systems. Which network architecture best meets secure design for these distributed sites?
- A metro fiber consortium carries traffic for several cities. One network team proposes skipping encryption on overlays because 'the underlay fiber is private.' Which conclusion is correct?
- Campus routers exchange routing updates and device management using protocols with authentication disabled, allowing trivial spoofing of peers. Which action best hardens protocol selection and configuration?
- A water utility’s OT network for pumps and PLCs was flatly trusted to the IT business network so billing apps could read meter data. Which segmentation approach is most appropriate?
- Public library Wi-Fi must serve patrons without reaching staff file shares or the integrated library system. Which wireless design best enforces that separation?
- Before accepting a vendor’s redesign of the city WAN and campus edge, security architects must review the proposal. Which review focus best applies secure design principles holistically?
- Core distribution switches for city hall lack redundant power supplies, and maintenance contracts have lapsed past end-of-support. Which operational concern is most security-relevant?
- Copper Ethernet runs for a municipal annex travel in unlocked hallway cable trays where visitors can reach the bundles. Which control best addresses transmission-media risk?
- Unknown devices freely attach to the campus LAN at a municipal operations center. Which control best restricts network admission?
- Roaming assessor laptops connect from hotels and home networks to municipal apps but lack host firewalls and modern endpoint detection. Which measure best addresses this network-component concern?
- Auditors find default SNMP community strings still enabled on routers that manage traffic for utility billing. Which hardening step is most urgent?
- A failover WAN link for the courthouse activates during outages but intentionally bypasses the primary firewall and IDS to 'guarantee connectivity.' Which principle should redesign follow?
- Administrators currently manage city firewalls from the same in-band production networks used by employees. Which management approach is preferred where practical?
- End-of-support wireless access points remain in city lobby SSIDs and no longer receive security patches. Which lifecycle action is most appropriate?
- City council chambers use cloud collaboration rooms and softphones with open dial-in numbers and weak meeting locks. Which practice best secures voice, video, and collaboration channels?
- County network admins still share a jump-host password over cleartext chat to reach core routers. Which change best implements secure remote administrative access?
- A water utility’s remote reservoirs rely on satellite and microwave backhaul that can be intercepted or spoofed. Which protection best addresses integrity and confidentiality for that data path?
- Telecom and hardware vendors dial into municipal SCADA support modems with no monitoring or access constraints. What should the security architect require for third-party connectivity?
- A sheriff’s office exchanges Criminal Justice Information (CJI) with state systems and also runs a public website. How should channel security be matched to data sensitivity?
- Hybrid municipal staff need to reach internal desktops from home. Which remote workforce access pattern is appropriate?
- A city allows vendor engineers into internal systems for after-hours repairs but rarely watches those sessions. What oversight should be added to third-party communication channels?