Free ISC2 Certified Information Systems Security Professional (CISSP) practice — 6 questions on Communication and Network Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Communication and Network Security
A retailer must isolate its PCI cardholder data environment (CDE) inside a large virtualized data center. Compliance requires that east-west traffic between CDE virtual machines and all other workloads be blocked by default, but the operations team frequently re-IPs and migrates VMs across hosts using vMotion-style live migration, so any solution tied to static IP addresses or physical port locations is unacceptable. Which architecture BEST satisfies these requirements?
SDN-based micro-segmentation with a distributed firewall enforces policy on workload identity/metadata (tags, security groups) rather than IP address or switch port, so policy follows the VM automatically through live migrations and re-IP events -- exactly the property needed here.
Question 2 of 6 · Communication and Network Security
A security architect must design remote access for a distributed workforce. Requirements: (1) every connection to internal line-of-business applications must be preceded by a continuous device posture check, (2) access must be granted per-application rather than to the full corporate network, and (3) traffic to approved SaaS platforms must NOT be backhauled through the corporate network, to keep SaaS latency low. Which solution BEST meets all three requirements?
ZTNA brokers evaluate device posture continuously and grant least-privilege, per-application tunnels only to authorized internal resources, while SaaS traffic is never routed through the corporate network -- satisfying the posture, per-app, and low-SaaS-latency requirements simultaneously.
Question 3 of 6 · Communication and Network Security
A network engineer must eliminate loops on a campus network where core switches have redundant Layer 2 links, while ensuring that failover after a link failure completes in well under one second to avoid disrupting VoIP calls. Which protocol should be implemented?
RSTP (802.1w) redesigns the STP state machine to achieve sub-second convergence after a topology change, meeting the strict failover requirement for latency-sensitive VoIP traffic.
Question 4 of 6 · Communication and Network Security
An organization is decommissioning Telnet on all network devices because credentials transit in cleartext. Some legacy switches still support only SSH version 1 for backward compatibility, in addition to SSH version 2. Which action represents the CISSP-recommended best practice for securing interactive management access to these devices?
SSH-2 fixed known cryptographic and integrity weaknesses present in SSH-1 (such as susceptibility to CRC32 attacks and weaker key exchange); best practice is to disable both Telnet and SSH-1, allowing only SSH-2 for management access.
Question 5 of 6 · Communication and Network Security
A company deploys 802.1X-based Network Access Control (NAC) on all wired switch ports. Endpoints that fail posture assessment must be automatically placed into an isolated remediation VLAN with access only to patch and AV update servers, without any manual switchport reconfiguration by network staff. Which configuration achieves this outcome?
RADIUS-driven dynamic VLAN assignment during 802.1X authentication (via attributes like Tunnel-Private-Group-ID) allows the switch to automatically place a device into the correct VLAN -- production or remediation -- based on the posture/authorization decision, with zero manual switchport changes.
Question 6 of 6 · Communication and Network Security
Which statement correctly differentiates IPsec transport mode from IPsec tunnel mode?
Transport mode protects only the payload and keeps the original IP header intact (typically host-to-host), while tunnel mode wraps the entire original packet -- header included -- inside a new IP packet, which is why tunnel mode is the standard choice for gateway-to-gateway and remote-access VPNs.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.