Step2Study
IT & TechnologyCISSP100% Free

ISC2 CISSP (Certified Information Systems Security Professional)

Practice bank
244 Qs
Real exam
125 Qs
Time limit
240 min
Passing
700 out of 1000 points

Exam blueprint

Security and Risk Management
15%
Asset Security
10%
Security Architecture and Engineering
13%
Communication and Network Security
13%
Identity and Access Management (IAM)
13%
Security Operations
13%
Software Development Security
10%
Security Assessment and Testing
13%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 125 questions each · 240 min · pass 70% · 244 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

ISC2 CISSP (Certified Information Systems Security Professional) practice test questions

Sample questions from the 244-question bank, with answers and explanations.

All questions
  1. 1. A security auditor is performing a vulnerability assessment on a company's internal network. During the scan, the auditor discovers several network switches that have not been configured with any security measures to prevent unauthorized devices from connecting to their ports. Specifically, an attacker could easily plug in a rogue device, spoof a legitimate MAC address, and potentially gain network access. Which feature should the network administrator implement on the switches to mitigate this risk?

    Communication and Network Security

    • A. VLAN tagging
    • B. ARP Inspection
    • C. 802.1X Port-Based Authentication
    • D. DHCP Snooping
    Show answer

    C. 802.1X Port-Based Authentication

    802.1X port-based authentication is the most comprehensive solution for preventing unauthorized devices from connecting to switch ports. It requires devices to authenticate before gaining network access, often integrating with a RADIUS server, and can be configured to dynamically assign VLANs or apply security policies.

  2. 2. A global enterprise is implementing a Software-Defined Networking (SDN) architecture to manage its vast and complex network infrastructure. The network operations team needs a component that can centralize the intelligence and decision-making for network forwarding, enabling programmatic control over network devices and services, and providing a unified view of the network state. Which SDN component fulfills this role?

    Communication and Network Security

    • A. SDN Control Plane
    • B. SDN Data Plane
    • C. SDN Management Plane
    • D. SDN Application Plane
    Show answer

    A. SDN Control Plane

    The SDN Control Plane is the 'brain' of the SDN architecture. It centralizes the network intelligence, makes decisions about how traffic should flow, and communicates these instructions to the data plane devices. This separation from the data plane enables programmatic control, automation, and a holistic view of the network.

  3. 3. A security auditor is reviewing the network design for a new, highly sensitive processing facility. The facility requires absolute assurance that no data can ever flow from its operational technology (OT) network, which controls critical machinery, to the external corporate network, while still allowing the corporate network to receive status updates from the OT network. Which of the following secure communication devices would BEST enforce this one-way data flow?

    Communication and Network Security

    • A. Data Diode
    • B. Application Gateway
    • C. Intrusion Prevention System (IPS)
    • D. Next-Generation Firewall (NGFW)
    Show answer

    A. Data Diode

    A data diode (or unidirectional gateway) is a hardware device that ensures data can only flow in one direction. It physically enforces a one-way data transfer, making it impossible for data to return from the corporate network to the OT network. This provides the highest level of assurance for preventing data exfiltration or external command injection into critical systems.

  4. 4. A company is implementing a new cloud-based application that processes highly confidential customer data. The security team requires that all communication between the company's on-premises network and the cloud application be encrypted, authenticated, and secured against eavesdropping and tampering. This secure channel must operate at a layer that is transparent to the end-user applications and provides end-to-end protection for the entire communication. Which technology is the most appropriate choice for establishing this secure communication channel?

    Communication and Network Security

    • A. SSL/TLS for applications
    • B. HTTPS
    • C. SSH Tunneling
    • D. IPsec VPN
    Show answer

    D. IPsec VPN

    IPsec VPN operates at the network layer (Layer 3), providing transparent, end-to-end encryption and authentication for all traffic between two networks (site-to-site) or a host and a network (remote access). This ensures all communication, regardless of the application, is secured against eavesdropping and tampering, fulfilling the requirements for a transparent and comprehensive secure channel.

  5. 5. A security auditor discovers that several network switches in a critical infrastructure environment are configured with default administrative credentials and unencrypted management protocols. The auditor recommends immediate action to prevent unauthorized access and manipulation of network traffic. Which network attack is most directly facilitated by these vulnerabilities?

    Communication and Network Security

    • A. Man-in-the-Middle (MITM)
    • B. Route Poisoning
    • C. Eavesdropping
    • D. Distributed Denial of Service (DDoS)
    Show answer

    A. Man-in-the-Middle (MITM)

    Default credentials and unencrypted management protocols on switches allow an attacker to gain unauthorized control over the switch. With control, the attacker can reconfigure routing, ARP tables, or port mirroring to intercept, alter, or redirect traffic, which are hallmarks of a Man-in-the-Middle attack.

  6. 6. An organization is deploying a new wireless network that will primarily serve guest users and employee personal devices. Due to the high density of users and the need to protect against various wireless threats, the security team requires a solution that offers enhanced protection against eavesdropping, traffic analysis, and credential compromise, even when users connect to seemingly legitimate access points (APs) that might actually be malicious. Which of the following wireless security protocols is BEST suited to address these concerns?

    Communication and Network Security

    • A. WPA3-Personal (SAE)
    • B. WPA3-Enterprise
    • C. WEP
    • D. WPA2-PSK
    Show answer

    A. WPA3-Personal (SAE)

    WPA3-Personal, utilizing Simultaneous Authentication of Equals (SAE), provides enhanced security over WPA2-PSK. It offers protection against dictionary attacks by preventing offline password guessing and provides forward secrecy, meaning a compromised session key will not compromise past sessions. This makes it more resilient to eavesdropping and traffic analysis, even against malicious APs trying to capture handshakes.

  7. 7. A security architect is designing a secure remote access solution for employees working from home. The solution must provide secure, encrypted communication between the employee's device and the corporate network over the public internet. It should also support various client operating systems and be relatively easy to deploy and manage. Which of the following secure communication channels is BEST suited for this scenario, providing both confidentiality and integrity?

    Communication and Network Security

    • A. IPsec VPN
    • B. Telnet
    • C. HTTP
    • D. SSH VPN
    Show answer

    A. IPsec VPN

    An IPsec VPN provides a secure, encrypted tunnel over an unsecure network (like the internet). It offers strong confidentiality, integrity, and authentication. IPsec is widely supported across various operating systems and devices, making it a robust and manageable solution for remote access to corporate resources.

  8. 8. A global organization is implementing a Software-Defined Wide Area Network (SD-WAN) to optimize traffic routing and improve application performance across its numerous branch offices. The solution needs to dynamically select the best path for application traffic based on real-time network conditions (e.g., latency, jitter, packet loss). Which component of the SD-WAN architecture is responsible for making these intelligent routing decisions?

    Communication and Network Security

    • A. Overlay Network
    • B. SD-WAN Orchestrator
    • C. SD-WAN Edge Appliance
    • D. Underlay Network
    Show answer

    B. SD-WAN Orchestrator

    The SD-WAN Orchestrator acts as the centralized brain of the SD-WAN, responsible for global policy enforcement, network monitoring, and making intelligent routing decisions based on real-time network conditions and application requirements. It pushes these decisions to the edge appliances.

  9. 9. A security auditor is reviewing the network design of a critical infrastructure environment. The design includes specialized devices that allow data flow in only one direction, preventing any return path for information. This is crucial for preventing external threats from affecting internal operational technology (OT) networks. What type of device is being described?

    Communication and Network Security

    • A. Intrusion Prevention System (IPS)
    • B. Data Diode
    • C. Proxy Server
    • D. Stateful Firewall
    Show answer

    B. Data Diode

    A data diode (or unidirectional gateway) is a hardware device that enforces one-way data flow, ensuring that data can only move from a less secure network to a more secure one, or vice-versa, without any return path. This is commonly used in critical infrastructure to protect OT networks.

  10. 10. A global manufacturing company is implementing a Software-Defined Wide Area Network (SD-WAN) solution to optimize traffic flow and improve application performance across its geographically dispersed sites. The company requires a component that can centralize the management of network policies, monitor application performance, and dynamically steer traffic based on real-time network conditions and business priorities. Which component of the SD-WAN architecture is responsible for these functions?

    Communication and Network Security

    • A. SD-WAN Gateway
    • B. SD-WAN Edge Device
    • C. SD-WAN Controller
    • D. SD-WAN Orchestrator
    Show answer

    D. SD-WAN Orchestrator

    The SD-WAN Orchestrator is the centralized management plane for the entire SD-WAN fabric. It allows administrators to define policies, monitor network and application performance, and provision configurations to all edge devices. It is responsible for the 'big picture' management and policy enforcement, while the controller often handles real-time path selection.

  11. 11. A financial institution is implementing a new trading platform that requires extremely low latency and deterministic packet delivery across its global network. The network team is evaluating a technology that can provide efficient forwarding decisions based on short, fixed-length labels rather than complex IP header lookups. Which networking technology is BEST suited for this requirement?

    Communication and Network Security

    • A. Software-Defined Networking (SDN)
    • B. Ethernet over IP (EoIP)
    • C. Multiprotocol Label Switching (MPLS)
    • D. Virtual Local Area Network (VLAN)
    Show answer

    C. Multiprotocol Label Switching (MPLS)

    MPLS is designed for high-performance packet forwarding by using short, fixed-length labels instead of traditional IP routing lookups. This significantly reduces latency and allows for traffic engineering, making it ideal for applications requiring deterministic delivery like financial trading platforms.

  12. 12. A network security team is deploying an Intrusion Prevention System (IPS) in an inline mode to protect a critical web application server. Which of the following is a primary risk associated with deploying an IPS in inline mode, particularly for latency-sensitive applications?

    Communication and Network Security

    • A. Inability to block malicious traffic effectively without impacting performance.
    • B. Increased false positive alerts requiring manual review.
    • C. The IPS becoming a single point of failure for network traffic.
    • D. Difficulty in scaling the IPS solution to handle increased traffic volume.
    Show answer

    C. The IPS becoming a single point of failure for network traffic.

    When an IPS is deployed inline, all network traffic must pass through it. If the IPS fails or experiences issues, it can halt or disrupt all traffic to the protected segment, making it a single point of failure.

  13. 13. An organization is deploying a new wireless network (WLAN) in a high-density environment, such as a large auditorium, where many users will connect simultaneously. The security team is concerned about the potential for denial-of-service (DoS) attacks and the need for robust frame protection against injection attacks. They also want to ensure backward compatibility with WPA2 devices where possible, but prioritize the strongest security features for new devices. Which wireless security standard addresses these concerns?

    Communication and Network Security

    • A. WPA2-Enterprise
    • B. WPA3
    • C. WPA-Personal
    • D. WEP
    Show answer

    B. WPA3

    WPA3 offers enhanced security features over WPA2, including more robust protection against brute-force attacks (SAE), improved frame protection (enhanced encryption of management frames), and better resilience against DoS attacks. It also maintains backward compatibility with WPA2 devices in mixed mode deployments.

  14. 14. A critical industrial control system (ICS) network needs to be isolated from the corporate IT network. The ICS network uses proprietary protocols and devices that are highly sensitive to latency and cannot tolerate any form of active inspection or proxying. However, a one-way data flow from the ICS network to the corporate network is required for monitoring purposes. Which secure network component is specifically designed to enforce this unidirectional data flow while maintaining strict isolation?

    Communication and Network Security

    • A. Next-Generation Firewall (NGFW)
    • B. Router with Access Control Lists (ACLs)
    • C. Intrusion Prevention System (IPS)
    • D. Data Diode
    Show answer

    D. Data Diode

    A data diode (or unidirectional gateway) is a hardware-based solution specifically designed to enforce one-way data flow, preventing any data from traversing in the opposite direction. This is crucial for highly sensitive environments like ICS where strict isolation and guaranteed unidirectional flow are paramount.

  15. 15. A company is experiencing slow network performance and occasional outages, particularly during peak hours. Investigation reveals that the network is being flooded with an unusually high volume of broadcast traffic, causing network devices to become overwhelmed. Which type of network attack is most likely occurring?

    Communication and Network Security

    • A. Man-in-the-Middle Attack
    • B. Buffer Overflow
    • C. SQL Injection
    • D. Smurf Attack
    Show answer

    D. Smurf Attack

    A Smurf attack is a type of Distributed Denial of Service (DDoS) attack that overwhelms a target network by flooding it with ICMP echo reply packets. This is achieved by sending ICMP echo requests to a network's broadcast address with the victim's spoofed IP address as the source.

  16. 16. An organization is deploying a new Software-Defined Wide Area Network (SD-WAN) solution across its geographically dispersed branch offices. The IT team needs a centralized component that can dynamically provision, configure, and monitor network services, as well as apply security policies consistently across the entire SD-WAN fabric. Which SD-WAN component fulfills this role?

    Communication and Network Security

    • A. SD-WAN Gateway
    • B. SD-WAN Edge Device
    • C. SD-WAN Orchestrator
    • D. SD-WAN Controller
    Show answer

    C. SD-WAN Orchestrator

    The SD-WAN Orchestrator is the centralized management plane that provides a single pane of glass for configuring, monitoring, and managing the entire SD-WAN deployment, including security policies, across all edge devices and gateways. The controller handles runtime decisions, while edge devices are the endpoints.

  17. 17. A security analyst is investigating a network attack where an attacker successfully intercepted and modified data being transmitted between two internal servers. The attacker then replayed the modified data to gain unauthorized access. Which of the following security services was primarily compromised in this attack?

    Communication and Network Security

    • A. Non-repudiation
    • B. Integrity
    • C. Availability
    • D. Confidentiality
    Show answer

    B. Integrity

    The core issue described is the modification of data in transit and its subsequent replay. This directly compromises the integrity of the data, as it was altered from its original state and then used maliciously.

  18. 18. A financial institution is implementing a new trading platform that requires extremely low latency and deterministic forwarding of network traffic between its trading servers and market data feeds. The network design must minimize jitter and packet loss, even under heavy load, and guarantee certain levels of service for critical data flows. Which network technology is specifically designed to provide these capabilities through traffic engineering and explicit path routing?

    Communication and Network Security

    • A. Ethernet over IP (EoIP)
    • B. Virtual Private Network (VPN)
    • C. Multiprotocol Label Switching (MPLS)
    • D. Generic Routing Encapsulation (GRE)
    Show answer

    C. Multiprotocol Label Switching (MPLS)

    MPLS is a high-performance, packet-forwarding technology that uses labels to make forwarding decisions. It allows for explicit path routing and traffic engineering, which is crucial for guaranteeing Quality of Service (QoS), minimizing latency, and ensuring deterministic forwarding required by high-frequency trading platforms.

  19. 19. A security analyst is investigating a series of network performance degradation incidents. Analysis reveals that the network is being flooded with ARP requests, causing switches to exhaust their CAM table entries and broadcast traffic excessively. This leads to legitimate traffic being dropped or delayed. Which of the following network attacks is MOST likely occurring?

    Communication and Network Security

    • A. MAC Flooding
    • B. DNS Amplification
    • C. SYN Flood
    • D. ARP Poisoning
    Show answer

    A. MAC Flooding

    MAC flooding attacks overwhelm a switch's Content Addressable Memory (CAM) table with fake MAC address-port mappings. When the CAM table is full, the switch enters 'fail-open' mode and acts like a hub, broadcasting all incoming traffic to all ports, leading to performance degradation and potential eavesdropping.

  20. 20. An organization is deploying a new application that will handle sensitive customer data. The application will reside on a server in a demilitarized zone (DMZ). To protect the internal network from potential compromises of the DMZ server, which network security component should be strategically placed between the DMZ and the internal network?

    Communication and Network Security

    • A. Load Balancer
    • B. Firewall
    • C. Intrusion Detection System (IDS)
    • D. Proxy Server
    Show answer

    B. Firewall

    A firewall is essential for controlling traffic flow and enforcing security policies between different network segments, such as between a DMZ and an internal network. It acts as a primary barrier to prevent unauthorized access.

  21. 21. A large university is upgrading its wireless network infrastructure. Due to the high density of users and the need for robust authentication against a central user directory (LDAP/Active Directory), the security team has decided to implement an enterprise-grade wireless security standard. Which standard provides the strongest authentication and encryption for this scenario?

    Communication and Network Security

    • A. WEP
    • B. WPA3-Enterprise
    • C. Open System Authentication
    • D. WPA2-PSK
    Show answer

    B. WPA3-Enterprise

    WPA3-Enterprise is the strongest and most current standard for enterprise wireless security, offering enhanced encryption and authentication mechanisms, including support for 192-bit cryptographic strength and robust EAP methods against RADIUS/LDAP servers. WPA2-PSK is for personal use, WEP is deprecated, and Open System provides no security.

  22. 22. A security architect is designing a new network for a global enterprise. The design must ensure secure communication between geographically dispersed sites over untrusted networks, provide data confidentiality and integrity, and authenticate communicating parties. Which of the following technologies is best suited to meet these requirements?

    Communication and Network Security

    • A. Virtual Local Area Network (VLAN)
    • B. Domain Name System Security Extensions (DNSSEC)
    • C. Network Address Translation (NAT)
    • D. Internet Protocol Security (IPsec)
    Show answer

    D. Internet Protocol Security (IPsec)

    IPsec provides a robust framework for securing IP communications by encrypting and authenticating IP packets. It is ideal for site-to-site VPNs, ensuring confidentiality, integrity, and authentication over public networks.

  23. 23. A security architect is reviewing the design of a new e-commerce platform. The platform requires secure communication between the web server and the database server, both residing within the same secure data center segment. While network segmentation is in place, the architect wants to ensure that specific application traffic between these two servers is encrypted and authenticated, without requiring full VPN tunnels or complex network-wide IPsec configurations. Which secure communication channel technology is most appropriate for this specific application-layer requirement?

    Communication and Network Security

    • A. Multi-Protocol Label Switching (MPLS)
    • B. Transport Layer Security (TLS)
    • C. Secure Shell (SSH)
    • D. Virtual Private Network (VPN)
    Show answer

    B. Transport Layer Security (TLS)

    TLS is designed to provide secure communication over a computer network, commonly used for encrypting application-layer traffic. It's ideal for securing specific server-to-server communication within a data center without the overhead of full network-layer VPNs.

  24. 24. A security architect is designing the network for a new high-security research facility. The facility requires strict network segmentation, where different research projects must be completely isolated from each other at Layer 2, even if they share the same physical switch infrastructure. Additionally, the design must logically separate administrative traffic from user data traffic. Which technology is MOST effective for achieving this logical Layer 2 segmentation?

    Communication and Network Security

    • A. Network Access Control (NAC)
    • B. Virtual Local Area Networks (VLANs)
    • C. Subnetting
    • D. Firewall Rules
    Show answer

    B. Virtual Local Area Networks (VLANs)

    VLANs provide logical Layer 2 segmentation, allowing devices on the same physical switch to be separated into different broadcast domains. This effectively isolates traffic between different projects and administrative/user traffic, meeting the requirements. Subnetting is Layer 3, firewalls filter traffic between segments, and NAC controls access.

  25. 25. A global enterprise is implementing a Software-Defined Networking (SDN) architecture to manage its diverse network infrastructure. The security team is concerned about ensuring consistent application of security policies across the entire network, regardless of the underlying hardware or vendor. Which SDN component is primarily responsible for translating high-level policy requirements into concrete network configurations and enforcing them across the data plane?

    Communication and Network Security

    • A. SDN Forwarding Plane
    • B. SDN Control Plane
    • C. SDN Data Plane
    • D. SDN Management Plane
    Show answer

    B. SDN Control Plane

    The SDN Control Plane is the 'brain' of the SDN architecture. It receives high-level policies from the management plane and translates them into forwarding instructions for the data plane devices, thereby enforcing security policies consistently across the network.

ISC2 CISSP (Certified Information Systems Security Professional) flashcards

Tap a card to flip it. 186 flashcards in the full deck.

  • 802.1X Port-Based Authentication

    Flip card

    An IEEE standard for port-based network access control that provides an authentication mechanism to devices wishing to attach to a LAN port or to establish a wireless connection.

    • Requires authentication before network access is granted.
    • Often integrates with RADIUS servers.
    • Can dynamically assign VLANs or apply policies post-authentication.
    Study this card →
  • SDN Control Plane

    Flip card

    In Software-Defined Networking (SDN), the control plane is the centralized component that holds the network's intelligence, makes routing decisions, and communicates these decisions to the data plane devices. It decouples network control from forwarding functions.

    • Centralizes network intelligence and decision-making.
    • Communicates with the data plane via southbound APIs (e.g., OpenFlow).
    • Enables network programmability and automation.
    Study this card →
  • Data Diode

    Flip card

    A hardware-based network security device that enforces one-way data flow between two networks. It prevents any data from flowing in the reverse direction, providing absolute assurance against data exfiltration or external network intrusion.

    • Physically enforces unidirectional data transfer.
    • Offers the highest level of network segregation security.
    • Commonly used in critical infrastructure (OT/ICS) and classified networks.
    Study this card →
  • IPsec VPN

    Flip card

    A Virtual Private Network (VPN) implementation that uses the IPsec protocol suite to provide secure, encrypted, and authenticated communication over an untrusted network like the internet.

    • Operates at the network layer (Layer 3).
    • Provides confidentiality, integrity, and authentication.
    • Can be configured as site-to-site or remote access VPNs.
    Study this card →
  • Man-in-the-Middle (MITM) Attack

    Flip card

    An attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.

    • Requires the attacker to intercept and control the communication path.
    • Can be facilitated by ARP spoofing, DNS spoofing, or compromised network devices.
    • Compromises confidentiality and integrity.
    Study this card →
  • WPA3-Personal (SAE)

    Flip card

    The latest standard for securing Wi-Fi networks using a pre-shared key, offering enhanced security features over WPA2-Personal. It uses Simultaneous Authentication of Equals (SAE) to provide stronger protection against offline dictionary attacks and introduce forward secrecy.

    • Uses Simultaneous Authentication of Equals (SAE) for robust key exchange.
    • Protects against offline dictionary attacks.
    • Provides forward secrecy, ensuring past session data remains secure.
    Study this card →
  • SD-WAN Orchestrator

    Flip card

    The centralized management and control component of an SD-WAN, responsible for policy enforcement, global network visibility, and intelligent routing decisions.

    • Acts as the 'brain' of the SD-WAN.
    • Monitors network health and application performance.
    • Pushes policies and routing decisions to edge devices.
    Study this card →
  • Multiprotocol Label Switching (MPLS)

    Flip card

    A routing technique in telecommunications networks that directs data from one network node to the next based on short path labels rather than long network addresses.

    • Reduces latency by avoiding complex IP header lookups.
    • Enables traffic engineering and quality of service (QoS).
    • Often used in core networks of service providers and large enterprises.
    Study this card →
  • IPS Inline Mode

    Flip card

    An Intrusion Prevention System deployment where all network traffic passes directly through the IPS, allowing it to actively block or prevent detected threats.

    • Acts as a gatekeeper, sits 'in-line' with network traffic.
    • Can actively drop malicious packets or reset connections.
    • Introduces latency and can be a single point of failure.
    Study this card →
  • WPA3

    Flip card

    The latest generation of Wi-Fi Protected Access security, offering enhanced cryptographic strength, improved authentication, and better resilience against common wireless attacks.

    • Uses Simultaneous Authentication of Equals (SAE) for stronger key establishment.
    • Provides Management Frame Protection (MFP) for integrity of management frames.
    • Offers WPA3-Personal for home, WPA3-Enterprise for corporate.
    Study this card →
  • Smurf Attack

    Flip card

    A DDoS attack in which the attacker sends a large number of ICMP echo requests to an IP broadcast address using a spoofed source IP address that belongs to the victim.

    • Relies on ICMP and IP broadcast addresses.
    • Amplifies traffic, causing a denial of service to the victim.
    • Mitigated by disabling IP directed broadcasts on routers.
    Study this card →
  • Integrity (CIA Triad)

    Flip card

    The assurance that information is accurate and complete, and has not been subjected to unauthorized modification or destruction.

    • Achieved through hashing, digital signatures, access controls.
    • Compromised by data tampering, unauthorized changes, or replay attacks.
    • Ensures trustworthiness and reliability of data.
    Study this card →
  • MAC Flooding

    Flip card

    A network attack that overwhelms a switch's Content Addressable Memory (CAM) table by sending a large number of frames with different source MAC addresses. This forces the switch to broadcast all incoming traffic to all ports, effectively turning it into a hub.

    • Targets Layer 2 switches.
    • Overwhelms the switch's CAM table.
    • Causes the switch to enter fail-open mode, broadcasting all traffic.
    Study this card →
  • Firewall

    Flip card

    A network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.

    • Can be hardware, software, or cloud-based.
    • Operates at various layers of the OSI model.
    • Essential for network segmentation and perimeter defense.
    Study this card →
  • WPA3-Enterprise

    Flip card

    The latest and most secure Wi-Fi Protected Access standard designed for enterprise environments, providing enhanced authentication and encryption.

    • Uses 802.1X for authentication, typically with RADIUS/EAP.
    • Supports 192-bit cryptographic strength for CNSA compliance.
    • Offers stronger protection against dictionary attacks and improved key management.
    Study this card →
  • IPsec

    Flip card

    A suite of protocols used to secure IP communications by providing authentication, integrity, and confidentiality services.

    • Operates at the network layer (Layer 3) of the OSI model.
    • Commonly used for Virtual Private Networks (VPNs).
    • Includes Authentication Header (AH) and Encapsulating Security Payload (ESP) protocols.
    Study this card →
  • Transport Layer Security (TLS)

    Flip card

    A cryptographic protocol designed to provide communication security over a computer network, widely used for encrypting web traffic and other application-layer data.

    • Operates at the transport layer of the OSI model.
    • Provides confidentiality, integrity, and authentication.
    • Successor to SSL (Secure Sockets Layer).
    Study this card →
  • Virtual Local Area Network (VLAN)

    Flip card

    A logical grouping of network devices that allows for segmentation of a local area network (LAN) into multiple broadcast domains, even if devices are on the same physical switch.

    • Operates at Layer 2 of the OSI model.
    • Enhances security by isolating traffic.
    • Improves network performance by reducing broadcast traffic.
    Study this card →
  • Intrusion Detection System (IDS)

    Flip card

    A security device that monitors network or system activities for malicious activity or policy violations and produces reports or alerts.

    • Monitors traffic for signatures or anomalies.
    • Primarily a detection and alerting tool.
    • Does not actively block traffic (unlike IPS).
    Study this card →
  • Port Security

    Flip card

    A switch feature that restricts input to an interface by limiting and identifying MAC addresses of stations allowed to access the port.

    • Prevents MAC address spoofing and MAC flooding attacks.
    • Allows static configuration of MAC addresses or dynamic learning up to a limit.
    • Can be configured to shut down the port, restrict traffic, or protect against violations.
    Study this card →
  • Virtual Extensible LAN (VXLAN)

    Flip card

    A network virtualization technology that encapsulates Layer 2 Ethernet frames in Layer 3 IP packets, creating a logical Layer 2 network over an existing Layer 3 infrastructure. It enables scalable multi-tenancy and larger virtual network segments in cloud data centers.

    • Extends Layer 2 networks over Layer 3 (referred to as an overlay network).
    • Uses a 24-bit VXLAN Network Identifier (VNI) for up to 16 million logical networks.
    • Solves the scalability limitations of traditional VLANs (4096 IDs).
    Study this card →
  • Datagram Transport Layer Security (DTLS)

    Flip card

    A communication protocol that provides security for datagram-based applications by allowing them to communicate in a way that prevents eavesdropping, tampering, or message forgery. It is based on TLS but adapted for unreliable transport protocols like UDP.

    • Provides security similar to TLS but over UDP.
    • Designed for applications sensitive to latency and packet loss (e.g., VoIP, gaming, IoT).
    • Handles packet reordering and loss inherent in UDP.
    Study this card →
  • Intrusion Prevention System (IPS) Inline Mode

    Flip card

    A deployment method for an IPS where the device is placed directly in the network's traffic path. This allows the IPS to actively inspect all passing traffic and take immediate action, such as blocking or dropping malicious packets, before they reach their intended target.

    • Acts as a gatekeeper, inspecting all traffic.
    • Enables real-time prevention and active blocking of threats.
    • Can introduce a single point of failure if not properly designed with bypass mechanisms.
    Study this card →
  • Software-Defined Networking (SDN)

    Flip card

    An architectural approach that decouples the network control and forwarding functions, enabling network control to become directly programmable and the underlying infrastructure to be abstracted from applications and network services.

    • Separates control plane from data plane.
    • Centralized network management and orchestration.
    • Enables network programmability and automation.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.