ISC2 CISSP (Certified Information Systems Security Professional) practice questions

244 free questions with answers and explanations.

Practice test
  1. 1.A network security team is deploying an Intrusion Prevention System (IPS) to protect critical internal servers. The team wants the IPS to actively block malicious traffic before it reaches the servers, rather than just alerting. To achieve this immediate preventive action, in which deployment mode should the IPS be configured?Communication and Network Security
  2. 2.A network security team is deploying an Intrusion Prevention System (IPS) to protect critical servers. The team wants the IPS to actively block malicious traffic before it reaches the servers, without relying on out-of-band communication or manual intervention for blocking. Which deployment mode should the IPS be configured for?Communication and Network Security
  3. 3.A manufacturing plant is implementing an Industrial Control System (ICS) network. To prevent unauthorized access and maintain system uptime, the security architect proposes a design where network traffic for critical control devices is strictly isolated from the corporate IT network. Data flow from the ICS network to the corporate network is permitted for monitoring purposes, but no traffic from the corporate network should ever reach the ICS network. Which network component is most suitable for enforcing this unidirectional data flow?Communication and Network Security
  4. 4.A security architect is designing a network for a new high-security research facility. The facility requires strict isolation between different research groups and between research data and administrative traffic, while still utilizing a shared physical network infrastructure. Which of the following network segmentation technologies is most appropriate to meet these requirements efficiently?Communication and Network Security
  5. 5.A financial institution is implementing a new trading platform that requires extremely low latency and high throughput for real-time market data distribution across its global network. The network architect is evaluating technologies that can optimize packet forwarding by avoiding repeated lookup processes at each hop, while also supporting quality of service (QoS) and traffic engineering. Which of the following technologies would BEST meet these requirements?Communication and Network Security
  6. 6.A security architect is designing a secure network for a new satellite ground station. Due to the extreme sensitivity of the data and the need for absolute isolation between the mission-critical network and the administrative network, any data transfer from the administrative network to the mission-critical network must be physically impossible, while one-way data flow from mission-critical to administrative is permitted for monitoring. Which secure communication channel component is the BEST choice to enforce this strict unidirectional data flow?Communication and Network Security
  7. 7.A security analyst is investigating a series of unauthorized access attempts originating from a compromised internal host. The attacker appears to be scanning for open ports on other internal systems and attempting to establish connections. Which network security device is primarily responsible for monitoring and analyzing network traffic for malicious activity and alerting administrators?Communication and Network Security
  8. 8.A cloud service provider is designing its data center network infrastructure to support multi-tenant environments. The design must ensure that each tenant's traffic is completely isolated from other tenants, even when sharing the same physical network hardware, and that network services can be rapidly provisioned and scaled. Which of the following networking technologies is BEST suited for achieving this scalable, isolated multi-tenancy?Communication and Network Security
  9. 9.A network security team is deploying an Intrusion Prevention System (IPS) to protect critical servers in their data center. The team wants the IPS to actively block malicious traffic in real-time before it reaches the servers, without significantly impacting network latency. Which deployment mode for the IPS would BEST achieve this objective?Communication and Network Security
  10. 10.A network security architect is designing a highly resilient and secure network for a critical infrastructure organization. The design must ensure that if a core network device fails, traffic can automatically reroute to an alternate path with minimal disruption, and that network changes are centrally managed and rapidly deployable. Which architectural approach BEST supports these requirements?Communication and Network Security
  11. 11.A company is deploying a new cloud-based application that requires secure communication between its on-premises data center and the cloud provider's Virtual Private Cloud (VPC). The solution must ensure data confidentiality and integrity during transit and allow for dynamic routing updates between networks. Which secure communication channel technology is best suited for this requirement?Communication and Network Security
  12. 12.A large e-commerce company is experiencing frequent distributed denial-of-service (DDoS) attacks targeting its web servers. These attacks often involve a flood of legitimate-looking HTTP requests, making them difficult to distinguish from normal user traffic. The security team needs a solution that can identify and mitigate these sophisticated application-layer attacks without blocking legitimate users. Which of the following security devices is BEST suited for this purpose?Communication and Network Security
  13. 13.A network architect is designing a highly scalable and resilient data center network using Software-Defined Networking (SDN). The goal is to decouple the control plane from the data plane to enable centralized management and programmatic network configuration. Which SDN component logically separates the intelligence for forwarding decisions from the actual packet forwarding process?Communication and Network Security
  14. 14.A network administrator is configuring network access for a new department. Users in this department need to access specific internal web applications and a database server. To minimize the attack surface, the administrator wants to ensure that only necessary ports are open from the department's subnet to the application and database servers. Which network security principle is the administrator applying by restricting ports to only those required?Communication and Network Security
  15. 15.A company is experiencing slow network performance and occasional outages, particularly during peak hours. Investigation reveals that the network is being flooded with an unusually high volume of broadcast traffic, causing network devices to become overwhelmed. Which type of network attack is most likely occurring?Communication and Network Security
  16. 16.A global enterprise is implementing a Software-Defined Networking (SDN) architecture to manage its diverse network infrastructure. The security team is concerned about ensuring consistent application of security policies across the entire network, regardless of the underlying hardware or vendor. Which SDN component is primarily responsible for translating high-level policy requirements into concrete network configurations and enforcing them across the data plane?Communication and Network Security
  17. 17.A security engineer is configuring a network device to prevent MAC address spoofing and limit the number of MAC addresses that can be learned on a specific port. This measure is intended to mitigate attacks that involve flooding the switch's MAC address table. Which network security component feature is being configured?Communication and Network Security
  18. 18.A security engineer is tasked with securing network access for devices connecting to a corporate switch port. The requirement is to ensure that only authorized devices, identified by their MAC addresses, can connect to specific ports, and to limit the number of MAC addresses allowed per port to prevent unauthorized devices from connecting. What feature of a network switch should the engineer configure?Communication and Network Security
  19. 19.A security engineer is configuring a network device to prevent MAC address spoofing and limit the number of devices that can connect to a specific switch port. The goal is to bind specific MAC addresses to specific ports or to restrict the total number of learned MAC addresses on a port to a predefined limit. Which feature should the engineer enable on the switch port to achieve this?Communication and Network Security
  20. 20.A security architect is designing the network for a new Internet of Things (IoT) deployment in a smart city project. The IoT devices have limited processing power and memory, and battery life is a critical concern. Secure communication is essential, but traditional TLS/SSL protocols are too resource-intensive. Which of the following secure communication protocols is BEST suited for these constrained IoT devices?Communication and Network Security
  21. 21.A financial institution is deploying a new trading platform that requires extremely low latency and high-speed data transfer between its various data centers. The network design must also support traffic engineering to prioritize critical trading data over less time-sensitive traffic. Which network technology is best suited to meet these requirements for efficient and prioritized data delivery?Communication and Network Security
  22. 22.A company is implementing a new wireless network (WLAN) for its corporate offices. The security team requires the strongest available encryption and authentication for all wireless client connections, including mutual authentication between the client and the access point, and dynamic per-user encryption keys. Which of the following WLAN security standards should be chosen?Communication and Network Security
  23. 23.A security architect is reviewing the design of a new e-commerce platform. The platform requires secure communication between the web server and the database server, both residing within the same secure data center segment. While network segmentation is in place, the architect wants to ensure that specific application traffic between these two servers is encrypted and authenticated, without requiring full VPN tunnels or complex network-wide IPsec configurations. Which secure communication channel technology is most appropriate for this specific application-layer requirement?Communication and Network Security
  24. 24.A network architect is designing a software-defined wide area network (SD-WAN) for an organization with multiple branch offices. The primary goal is to optimize traffic routing based on application performance requirements and link quality, while also ensuring secure overlay tunnels. Which SD-WAN component is responsible for centrally managing policies, configurations, and orchestrating connectivity across the entire SD-WAN fabric?Communication and Network Security
  25. 25.A security architect is designing a secure wireless network for a government agency handling classified information. The primary concern is protecting against passive eavesdropping and ensuring strong mutual authentication between wireless clients and access points (APs). The solution must use the strongest available encryption and authentication protocols for enterprise environments. Which wireless security standard and protocol combination should be recommended?Communication and Network Security
  26. 26.An organization is considering implementing a Software-Defined Networking (SDN) architecture. One of the key benefits cited is the ability to programmatically control network devices and dynamically adjust network configurations based on real-time demands. Which SDN component is primarily responsible for translating high-level network policies into low-level instructions for network devices?Communication and Network Security
  27. 27.A security architect is designing a new network for a global enterprise. The design must ensure secure communication between geographically dispersed sites over untrusted networks, provide data confidentiality and integrity, and authenticate communicating parties. Which of the following technologies is best suited to meet these requirements?Communication and Network Security
  28. 28.A security architect is designing a network for a new high-security research facility. The facility will have multiple departments, each handling sensitive and distinct research data. The architect needs to ensure that traffic from one department cannot directly access resources in another department without passing through a central security inspection point, even if they are on the same physical switch. Which of the following network segmentation techniques is BEST suited for this requirement?Communication and Network Security
  29. 29.An organization is deploying a new application that will handle sensitive customer data. The application will reside on a server in a demilitarized zone (DMZ). To protect the internal network from potential compromises of the DMZ server, which network security component should be strategically placed between the DMZ and the internal network?Communication and Network Security
  30. 30.A security analyst is investigating a series of network performance degradation incidents. Analysis reveals that the network is being flooded with ARP requests, causing switches to exhaust their CAM table entries and broadcast traffic excessively. This leads to legitimate traffic being dropped or delayed. Which of the following network attacks is MOST likely occurring?Communication and Network Security
  31. 31.A network security team is deploying an Intrusion Prevention System (IPS) in an inline mode to protect a critical web application server. Which of the following is a primary risk associated with deploying an IPS in inline mode, particularly for latency-sensitive applications?Communication and Network Security
  32. 32.A security auditor discovers that several network switches in a critical infrastructure environment are configured with default administrative credentials and unencrypted management protocols. The auditor recommends immediate action to prevent unauthorized access and manipulation of network traffic. Which network attack is most directly facilitated by these vulnerabilities?Communication and Network Security
  33. 33.A large university is upgrading its wireless network infrastructure. Due to the high density of users and the need for robust authentication against a central user directory (LDAP/Active Directory), the security team has decided to implement an enterprise-grade wireless security standard. Which standard provides the strongest authentication and encryption for this scenario?Communication and Network Security
  34. 34.A security architect is designing the network for a new high-security research facility. The facility requires strict network segmentation, where different research projects must be completely isolated from each other at Layer 2, even if they share the same physical switch infrastructure. Additionally, the design must logically separate administrative traffic from user data traffic. Which technology is MOST effective for achieving this logical Layer 2 segmentation?Communication and Network Security
  35. 35.A security auditor is performing a vulnerability assessment on a company's internal network. During the scan, the auditor discovers several network switches that have not been configured with any security measures to prevent unauthorized devices from connecting to their ports. Specifically, an attacker could easily plug in a rogue device, spoof a legitimate MAC address, and potentially gain network access. Which feature should the network administrator implement on the switches to mitigate this risk?Communication and Network Security
  36. 36.A company is implementing a new cloud-based application that processes highly confidential customer data. The security team requires that all communication between the company's on-premises network and the cloud application be encrypted, authenticated, and secured against eavesdropping and tampering. This secure channel must operate at a layer that is transparent to the end-user applications and provides end-to-end protection for the entire communication. Which technology is the most appropriate choice for establishing this secure communication channel?Communication and Network Security
  37. 37.A security auditor is reviewing the network design for a new, highly sensitive processing facility. The facility requires absolute assurance that no data can ever flow from its operational technology (OT) network, which controls critical machinery, to the external corporate network, while still allowing the corporate network to receive status updates from the OT network. Which of the following secure communication devices would BEST enforce this one-way data flow?Communication and Network Security
  38. 38.A global enterprise is implementing a Software-Defined Networking (SDN) architecture to manage its vast and complex network infrastructure. The network operations team needs a component that can centralize the intelligence and decision-making for network forwarding, enabling programmatic control over network devices and services, and providing a unified view of the network state. Which SDN component fulfills this role?Communication and Network Security
  39. 39.A global organization is implementing a Software-Defined Wide Area Network (SD-WAN) to optimize traffic routing and improve application performance across its numerous branch offices. The solution needs to dynamically select the best path for application traffic based on real-time network conditions (e.g., latency, jitter, packet loss). Which component of the SD-WAN architecture is responsible for making these intelligent routing decisions?Communication and Network Security
  40. 40.A critical industrial control system (ICS) network needs to be isolated from the corporate IT network. The ICS network uses proprietary protocols and devices that are highly sensitive to latency and cannot tolerate any form of active inspection or proxying. However, a one-way data flow from the ICS network to the corporate network is required for monitoring purposes. Which secure network component is specifically designed to enforce this unidirectional data flow while maintaining strict isolation?Communication and Network Security
  41. 41.A security architect is designing a secure remote access solution for employees working from home. The solution must provide secure, encrypted communication between the employee's device and the corporate network over the public internet. It should also support various client operating systems and be relatively easy to deploy and manage. Which of the following secure communication channels is BEST suited for this scenario, providing both confidentiality and integrity?Communication and Network Security
  42. 42.An organization is deploying a new wireless network that will primarily serve guest users and employee personal devices. Due to the high density of users and the need to protect against various wireless threats, the security team requires a solution that offers enhanced protection against eavesdropping, traffic analysis, and credential compromise, even when users connect to seemingly legitimate access points (APs) that might actually be malicious. Which of the following wireless security protocols is BEST suited to address these concerns?Communication and Network Security
  43. 43.A security auditor is reviewing the network design of a critical infrastructure environment. The design includes specialized devices that allow data flow in only one direction, preventing any return path for information. This is crucial for preventing external threats from affecting internal operational technology (OT) networks. What type of device is being described?Communication and Network Security
  44. 44.An organization is deploying a new wireless network (WLAN) in a high-density environment, such as a large auditorium, where many users will connect simultaneously. The security team is concerned about the potential for denial-of-service (DoS) attacks and the need for robust frame protection against injection attacks. They also want to ensure backward compatibility with WPA2 devices where possible, but prioritize the strongest security features for new devices. Which wireless security standard addresses these concerns?Communication and Network Security
  45. 45.A financial institution is implementing a new trading platform that requires extremely low latency and deterministic packet delivery across its global network. The network team is evaluating a technology that can provide efficient forwarding decisions based on short, fixed-length labels rather than complex IP header lookups. Which networking technology is BEST suited for this requirement?Communication and Network Security
  46. 46.A global manufacturing company is implementing a Software-Defined Wide Area Network (SD-WAN) solution to optimize traffic flow and improve application performance across its geographically dispersed sites. The company requires a component that can centralize the management of network policies, monitor application performance, and dynamically steer traffic based on real-time network conditions and business priorities. Which component of the SD-WAN architecture is responsible for these functions?Communication and Network Security
  47. 47.A security analyst is investigating a network attack where an attacker successfully intercepted and modified data being transmitted between two internal servers. The attacker then replayed the modified data to gain unauthorized access. Which of the following security services was primarily compromised in this attack?Communication and Network Security
  48. 48.A financial institution is implementing a new trading platform that requires extremely low latency and deterministic forwarding of network traffic between its trading servers and market data feeds. The network design must minimize jitter and packet loss, even under heavy load, and guarantee certain levels of service for critical data flows. Which network technology is specifically designed to provide these capabilities through traffic engineering and explicit path routing?Communication and Network Security
  49. 49.An organization is deploying a new Software-Defined Wide Area Network (SD-WAN) solution across its geographically dispersed branch offices. The IT team needs a centralized component that can dynamically provision, configure, and monitor network services, as well as apply security policies consistently across the entire SD-WAN fabric. Which SD-WAN component fulfills this role?Communication and Network Security
  50. 50.A security architect is designing a network for a new branch office that will handle sensitive customer data. The design requires a mechanism to ensure that all traffic between the branch office and the main data center is encrypted and authenticated at the network layer, without requiring application-specific configurations. Which protocol suite is BEST suited for this requirement?Communication and Network Security