Network Security

Worth 24% of the ISC2 Certified in Cybersecurity (CC) exam. CertClue has 95 questions on this objective.

What this objective covers

Segmentation Patterns and Where to Apply Them

Segmentation is the most frequently correct answer in CC network questions. Knowing the specific patterns lets you pick the right one rather than answering generically.

Exam tip. When a device cannot be secured directly, segmentation is almost always the intended answer.

OSI Layers and Where Security Controls Sit

CC keeps networking light but expects you to place addresses, ports and devices at the right layer, because that determines which control applies to a described problem.

Exam tip. Match the control to the layer of the identifier the question describes.

Firewalls, IDS, IPS and Segmentation

Each defensive technology answers a different requirement. The exam wording - detect versus block, contain versus filter - decides which is correct.

Exam tip. If a device cannot be hardened or patched, the answer is almost always segmentation.

Insecure Protocols and Their Secure Replacements

A reliable source of marks. Learn these as pairs, because questions usually describe clear-text credentials and ask what should be used instead.

Exam tip. A VPN protects traffic in transit. It does nothing about malware already on the endpoint.

Wireless Security in Practice

Wireless extends the network beyond the walls, so it needs authentication and encryption appropriate to what is behind it.

Exam tip. Individual accountability or per-user revocation always points to Enterprise mode rather than a shared passphrase.

Common Ports and What Their Exposure Means

CC expects familiarity with a small set of ports, and more importantly with which ones should never face the internet.

Exam tip. The exam cares less about memorising every port than about knowing which exposures are dangerous.

Cloud Service and Deployment Models

CC covers cloud at a conceptual level. The distinctions that matter are who manages what, and who the infrastructure serves.

Exam tip. Data classification and access control stay with the customer under every model, without exception.

Network Documentation and Change Discipline

Undocumented networks cannot be defended or recovered. CC treats documentation as an operational security control.

Exam tip. Forgotten and undocumented systems are the ones left unpatched, and they are disproportionately the ones exploited.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. At which OSI layer do IP addresses operate?

  • A. Layer 3, the Network layercorrect
  • B. Layer 2, the Data Link layer
  • C. Layer 4, the Transport layer
  • D. Layer 7, the Application layer

IP addressing and routing are network layer functions. MAC addresses operate at layer 2, ports at layer 4, and application protocols at layer 7.

2. What does network address translation provide in addition to conserving public IP addresses?

  • A. It guarantees availability during a denial of service attack
  • B. Internal host addresses are hidden from external observerscorrect
  • C. All traffic passing through it is automatically encrypted
  • D. Malware in the traffic stream is detected and removed

Because outbound connections appear to come from the translated public address, the internal addressing scheme is not visible externally, which frustrates reconnaissance. This is a useful side benefit but not a security control in its own right, and it does not inspect, filter or encrypt anything.

Work the whole objective

The full ISC2 Certified in Cybersecurity bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISC2 Certified in Cybersecurity practice test

The other ISC2 Certified in Cybersecurity objectives