Lesson Fourteen established how network communications operate through the OSI and TCP/IP models, addressing, routing, switching, segmentation, secure protocols, software-defined networking, cloud networking, and traffic flows.
Lesson Fifteen asks a different question:
How do we keep the actual network infrastructure trustworthy after the architecture has been designed?
A well-designed network can still fail if:
routers use default credentials;
switches run unsupported firmware;
management interfaces are exposed;
firewalls contain obsolete rules;
network devices have no redundant power;
copper cabling is accessible to unauthorized persons;
wireless signals extend outside controlled areas;
compromised laptops are permitted onto internal networks;
endpoints operate without host-based security;
critical network components reach End of Support without replacement.
The current CISSP examination places these topics primarily under Domain 4, Objective 4.2 β Secure network components.
The official objective currently contains four major areas:
operation of infrastructure, including redundant power, warranties, and support;
transmission media, including physical protection and signal-propagation quality;
Network Access Control systems, including physical and virtual solutions;
endpoint security, including host-based protection.
NIST's modern enterprise-network guidance similarly treats device/endpoint protection, security appliances, cloud-connected infrastructure, micro-segmentation, and secure network operations as interconnected components of the enterprise security architecture.
The central Lesson Fifteen question is:
How should network infrastructure, transmission media, access-control mechanisms, management interfaces, and endpoints be protected so the network architecture remains secure, available, supportable, and trustworthy in operation?
| Lesson Topic | CISSP Alignment |
|---|---|
| Infrastructure operations | Domain 4.2 |
| Redundant power | Domain 4.2 |
| Hardware warranties | Domain 4.2 |
| Vendor support | Domain 4.2 |
| End of Support | Domain 4.2 supporting concept |
| Firmware maintenance | Domain 4.2 |
| Configuration management | Domain 4.2 supporting concept |
| Routers | Supporting network component |
| Switches | Supporting network component |
| Firewalls | Supporting network component |
| Proxies | Supporting network component |
| Load balancers | Supporting network component |
| IDS/IPS | Supporting network component |
| Network taps / SPAN | Supporting monitoring component |
| Transmission media | Domain 4.2 |
| Copper cabling | Domain 4.2 |
| Fiber-optic media | Domain 4.2 |
| Wireless media | Domain 4.2 |
| Physical media protection | Domain 4.2 |
| Signal propagation | Domain 4.2 |
| Attenuation | Domain 4.2 |
| EMI/RFI | Domain 4.2 |
| Crosstalk | Domain 4.2 |
| Network Access Control | Domain 4.2 |
| Physical NAC | Domain 4.2 |
| Virtual NAC | Domain 4.2 |
| 802.1X | Supporting NAC concept |
| Supplicant | Supporting NAC concept |
| Authenticator | Supporting NAC concept |
| Authentication server | Supporting NAC concept |
| RADIUS | Supporting NAC concept |
| Endpoint posture assessment | Domain 4.2 |
| Quarantine networks | Domain 4.2 |
| Endpoint security | Domain 4.2 |
| Host firewall | Domain 4.2 |
| Anti-malware | Domain 4.2 |
| EDR | Domain 4.2 |
| HIDS/HIPS | Domain 4.2 |
| Disk encryption | Domain 4.2 supporting concept |
| Application control | Domain 4.2 |
| MDM/UEM | Domain 4.2 supporting concept |
| Endpoint patching | Domain 4.2 |
| BYOD controls | Domain 4.2 supporting concept |
The four explicit current 4.2 categories are infrastructure operations, transmission media, NAC, and endpoint security.
After completing this lesson, you should be able to:
Explain why network architecture and network-component security are different.
Explain infrastructure operational security.
Describe high-availability network design.
Explain redundant power for network devices.
Explain hardware redundancy.
Explain link redundancy.
Explain failover.
Explain why warranties and vendor support are security considerations.
Explain End-of-Life and End-of-Support risks.
Explain firmware security.
Explain secure network-device baselines.
Explain network-device configuration management.
Explain secure administrative access.
Explain why management interfaces are high-value targets.
Explain the role of routers in infrastructure security.
Explain the role of switches.
Explain firewall functions.
Distinguish packet filtering from stateful inspection.
Explain application-aware and next-generation firewall concepts.
Explain proxy security functions.
Explain reverse proxies.
Explain load balancers.
Explain IDS and IPS.
Distinguish IDS from IPS.
Explain network taps and switched-port analyzers conceptually.
Explain why security monitoring needs visibility.
Identify common transmission media.
Compare copper and fiber.
Explain signal attenuation.
Explain electromagnetic interference.
Explain radio-frequency interference.
Explain crosstalk.
Explain physical cable protection.
Explain why fiber has different interception characteristics from copper.
Explain wireless signal-propagation risks.
Define Network Access Control.
Explain pre-admission and post-admission NAC.
Explain 802.1X conceptually.
Define supplicant.
Define authenticator.
Define authentication server.
Explain RADIUS's role in NAC.
Explain endpoint posture assessment.
Explain quarantine and remediation networks.
Explain guest network handling.
Explain BYOD implications.
Explain agent-based and agentless NAC.
Explain why MAC-address authentication is weaker than strong identity.
Explain endpoint security.
Explain host firewalls.
Explain endpoint anti-malware.
Explain EDR.
Explain HIDS and HIPS.
Explain application allowlisting.
Explain disk encryption.
Explain endpoint patch management.
Explain mobile-device management.
Explain endpoint hardening.
Explain endpoint telemetry.
Apply CISSP reasoning to network-infrastructure scenarios.
Lesson Fourteen answered questions such as:
Where should segmentation occur?
Which systems belong in separate security zones?
Which protocols should be allowed?
Where should firewalls be placed?
Lesson Fifteen asks:
Can the components implementing that architecture actually be trusted?
Architecture says:
INTERNET
β
βΌ
FIREWALL
β
βΌ
DMZ
β
βΌ
INTERNAL NETWORK
But suppose the firewall:
runs unsupported firmware;
has a default administrator password;
sends no security logs;
has only one power supply.
The architecture may be sound.
The implementation is not.
NETWORK DESIGN
β
βΌ
NETWORK COMPONENTS
β
βΌ
SECURE CONFIGURATION
β
βΌ
SUPPORTED FIRMWARE
β
βΌ
RESTRICTED MANAGEMENT
β
βΌ
MONITORING
β
βΌ
REDUNDANCY
β
βΌ
TRUSTWORTHY OPERATION
Network infrastructure includes components such as:
routers;
switches;
firewalls;
wireless controllers;
load balancers;
security appliances;
management systems.
If these fail, applications may become unreachable even when the applications themselves remain healthy.
Suppose:
all servers operate normally;
storage remains available;
identity systems function.
But the core router fails.
Users still lose access.
Therefore:
Network infrastructure is part of the organization's availability architecture.
For every critical network component, ask:
What happens if it fails?
Is there a replacement?
Does it have redundant power?
Is vendor support still available?
Can its configuration be restored?
Is firmware current?
Who can administer it?
How is it monitored?
Redundancy provides additional components or paths so failure of one element does not automatically eliminate the service.
βββ ROUTER A βββ
INTERNET βββββ€ βββββ INTERNAL
βββ ROUTER B βββ
Two devices do not provide meaningful resilience if they share the same single point of failure.
Example:
ROUTER A βββ
βββ SINGLE POWER STRIP
ROUTER B βββ
Power-strip failure removes both routers.
A common-mode failure is one event capable of disabling multiple supposedly redundant components.
Examples include:
shared power circuit;
shared cooling system;
shared cable route;
common upstream carrier;
identical defective firmware.
When evaluating redundancy, ask:
Are the redundant components independent enough that one event will not defeat all of them?
The current exam outline directly identifies redundant power as an example of infrastructure operations.
A high-value network device may have:
dual power supplies;
separate power circuits;
UPS support;
generator-backed power.
POWER SOURCE A
β
βΌ
PSU A βββββββ
β
ROUTER
β
PSU B βββββββ
β²
β
POWER SOURCE B
Ideally, the two paths should not unnecessarily share the same upstream failure point.
Two power supplies connected to:
the same single failed outlet
may not provide meaningful resilience.
Critical infrastructure can use multiple devices.
Examples:
FIREWALL A
β
βββ High Availability
β
FIREWALL B
If Firewall A fails, Firewall B may assume operation.
In an active/passive model:
ACTIVE DEVICE
β
βΌ
Handles traffic
STANDBY DEVICE
β
βΌ
Waits for failover
In an active/active design, multiple devices may simultaneously process traffic.
Benefits can include:
capacity;
resilience.
However, state synchronization and design complexity increase.
SITE A
β \
β \
ISP 1 ISP 2
β β
ββββββ
β
SITE B
Multiple links can improve resilience.
Two circuits purchased under different product names may still traverse:
the same underground conduit.
A single construction accident could disable both.
Therefore assess actual physical diversity where required.
Failover transfers functionality to a backup component when the primary component becomes unavailable.
PRIMARY
β
X FAILURE
β
βΌ
STANDBY
β
βΌ
SERVICE CONTINUES
A configuration labeled:
βHigh Availabilityβ
does not guarantee successful failover.
Test:
state synchronization;
routing;
sessions;
management access;
recovery behavior.
The official 4.2 objective explicitly includes:
warranty;
support.
This reflects a managerial principle:
Secure infrastructure must also be maintainable and supportable.
A warranty may provide:
repair;
replacement;
hardware support.
If a mission-critical switch fails and replacement takes six weeks, availability risk increases.
Vendor support may provide:
firmware;
patches;
technical assistance;
security advisories;
replacement hardware.
When selecting a network component, do not evaluate only:
purchase price.
Also evaluate:
support lifetime;
replacement availability;
patch access;
vendor response.
A router can continue forwarding packets after support ends.
But:
Functional does not mean acceptably secure.
An unsupported network device may stop receiving:
vulnerability fixes;
firmware updates;
vendor assistance.
PROCURE
β
βΌ
DEPLOY
β
βΌ
OPERATE
β
βΌ
MAINTAIN
β
βΌ
SUPPORT WINDOW DECLINES
β
βΌ
REPLACE / MIGRATE
β
βΌ
RETIRE
Track support status before the device becomes unsupported.
Do not wait for:
a critical zero-day vulnerability
to discover the router has been unsupported for two years.
Routers and switches commonly contain:
operating systems;
firmware;
boot loaders;
embedded services.
They therefore require security maintenance just like servers.
Vulnerable firmware may permit:
remote compromise;
privilege escalation;
persistent unauthorized access.
A mature process includes:
VENDOR ADVISORY
β
βΌ
ASSESS EXPOSURE
β
βΌ
TEST UPDATE
β
βΌ
CHANGE APPROVAL
β
βΌ
DEPLOY
β
βΌ
VERIFY
A secure baseline defines the approved security configuration for a device class.
Examples may include:
approved firmware version;
required logging;
allowed management protocols;
administrator authentication;
unused services disabled;
time synchronization.
Without a baseline, security cannot easily distinguish:
approved configuration
from:
unauthorized configuration.
Example:
APPROVED:
SSH only
TEMPORARY CHANGE:
Telnet enabled
LATER:
Telnet never disabled
The device has drifted from its secure baseline.
Network-device configurations should be backed up according to operational requirements.
If a router fails:
REPLACEMENT ROUTER
β
βΌ
RESTORE APPROVED CONFIG
β
βΌ
VALIDATE
β
βΌ
SERVICE RESTORED
Configuration files may contain:
topology information;
encrypted or hashed credentials;
network addresses;
security rules.
They are sensitive assets.
A router administrator may be able to:
redirect traffic;
disable interfaces;
change ACLs;
modify routing;
view configurations.
Compromise can affect the entire network.
Controls may include:
dedicated management networks;
MFA;
SSH;
least privilege;
logging;
source restrictions.
Legacy management methods can expose:
credentials;
administrative commands.
Prefer encrypted authenticated management channels.
ADMIN WORKSTATION
β
βΌ
MANAGEMENT NETWORK
β
ββββββΌβββββ
βΌ βΌ βΌ
RTR1 SW1 FW1
Users should not automatically reach privileged network-management interfaces.
A separate management path can improve:
isolation;
resilience;
emergency recovery.
But it must itself be strongly protected.
Poor:
Username: admin
Used by 10 administrators
This weakens accountability.
Use:
individually attributable accounts;
strong authentication;
privilege separation;
logging.
AAA provides a useful framework:
AUTHENTICATION
Who are you?
β
βΌ
AUTHORIZATION
What may you do?
β
βΌ
ACCOUNTING
What did you do?
Detailed AAA appears later in Domain 5, but it is highly relevant to network-device management.
Routers are critical because they determine where traffic flows between IP networks.
A compromised router may allow an attacker to:
redirect traffic;
alter routes;
disrupt connectivity;
expose management functions.
Conceptually:
MINIMIZE SERVICES
+
SECURE MANAGEMENT
+
ROUTE PROTECTION
+
ACCESS CONTROL
+
LOGGING
+
PATCHING
Switches can provide:
VLANs;
port controls;
traffic forwarding;
Layer 2 security features.
Unused physical ports should be managed according to risk.
Leaving active unused ports in public areas can enable unauthorized network connection.
WALL JACK
β
βΌ
SWITCH PORT
β
βΌ
AUTHORIZED DEVICE?
β
βββ΄ββ
YES NO
β β
ALLOW BLOCK / NAC
NIST describes firewalls as devices or programs that control network traffic between networks or hosts with different security postures.
A firewall enforces:
Which communication is permitted across a security boundary.
Basic packet filtering may evaluate:
source IP;
destination IP;
protocol;
source/destination port.
A stateful firewall tracks connection state.
CLIENT ββ SYN βββΊ SERVER
β
βΌ
FIREWALL TRACKS SESSION
β
βΌ
RETURN TRAFFIC
MATCHES STATE?
The firewall can distinguish:
expected return traffic
from:
unsolicited traffic.
Application-aware firewalls may understand aspects of:
HTTP;
applications;
users;
application behavior.
This provides policy capabilities beyond basic IP and port filtering.
A next-generation firewall may combine capabilities such as:
stateful inspection;
application identification;
intrusion prevention;
user-aware policy.
Capabilities vary by product.
A strong security approach generally permits required communication rather than allowing everything and attempting to block only known bad activity.
Conceptually:
DENY BY DEFAULT
β
βΌ
ALLOW REQUIRED FLOWS
β
βΌ
LOG IMPORTANT EVENTS
Over time:
TEMPORARY RULE
β
βΌ
PROJECT FINISHES
β
βΌ
RULE REMAINS
β
βΌ
UNNECESSARY EXPOSURE
Firewall rules require lifecycle review.
A host-based firewall runs on an endpoint or server.
NIST's firewall guidance distinguishes network and host-based firewall capabilities.
NETWORK FIREWALL
β
βΌ
HOST FIREWALL
β
βΌ
APPLICATION
The host firewall helps maintain protection even when devices are:
mobile;
remote;
connected to other networks.
A proxy intermediates communication.
CLIENT
β
βΌ
PROXY
β
βΌ
SERVER
A forward proxy commonly acts on behalf of clients.
It may provide:
web filtering;
policy enforcement;
logging.
A reverse proxy acts in front of servers.
INTERNET
β
βΌ
REVERSE PROXY
β
βΌ
APPLICATION SERVERS
Depending on design:
hides backend infrastructure;
terminates TLS;
filters requests;
distributes traffic.
A load balancer distributes connections or requests across multiple resources.
βββ SERVER A
CLIENT ββΊ LBβββ SERVER B
βββ SERVER C
Load balancing can improve:
availability;
performance;
resilience.
It can also become:
a critical infrastructure dependency.
A redundant server farm with only one load balancer can still have:
one critical failure point.
An IDS monitors activity and generates alerts when suspicious behavior is detected.
An IPS can operate inline and take automated action such as:
dropping packets;
blocking sessions.
| IDS | IPS |
|---|---|
| Primarily detective | Detective + preventive |
| Often passive/out-of-band | Often inline |
| Alerts | May block |
| Lower risk of blocking legitimate traffic | False positives may affect availability |
Signature-based detection looks for known patterns associated with known threats.
Strength:
Recognizes known attacks well.
Limitation:
Unknown attacks may not match a signature.
Anomaly-based approaches identify deviations from expected behavior.
Strength:
Potentially detects previously unknown activity.
Limitation:
May generate false positives.
An IDS cannot analyze traffic it never receives.
Therefore network monitoring design must consider:
encrypted traffic;
switching architecture;
cloud traffic;
east-west traffic.
A switch can copy traffic from selected interfaces to a monitoring interface.
TRAFFIC
A ββββΊ SWITCH ββββΊ B
β
ββββΊ MONITOR
A network tap provides a mechanism for observing traffic on a link.
Taps may be designed specifically for:
monitoring;
packet capture;
security analysis.
Monitoring architecture should provide:
adequate visibility;
appropriate capacity;
controlled access to captured traffic.
Captured network traffic may itself contain sensitive information.
The current CISSP outline explicitly requires candidates to secure transmission media, including:
physical security of the media;
signal-propagation quality.
At CISSP level, understand:
COPPER
FIBER
WIRELESS / RADIO
Each has different:
performance;
distance;
interference;
interception considerations.
Copper cabling transmits information using electrical signals.
Common forms include:
twisted pair;
coaxial cable.
Copper is:
widely available;
relatively easy to install;
cost-effective in many LAN environments.
Electrical signals may be affected by:
electromagnetic interference;
radio-frequency interference;
crosstalk;
attenuation.
Physical tapping is also a concern.
Twisting conductors helps reduce electromagnetic interference and crosstalk.
Common network cabling uses twisted-pair designs.
Shielding can provide additional resistance against interference where appropriate.
Selection depends on:
environment;
performance;
cost;
installation requirements.
Crosstalk occurs when a signal in one communication path creates unwanted interference in another.
Conceptually:
CABLE A SIGNAL
β
βββββ unwanted coupling ββββΊ CABLE B
Crosstalk can cause:
communication errors;
degraded performance.
It can also be relevant to information leakage under certain conditions.
EMI can originate from:
motors;
electrical equipment;
power systems.
RFI is interference caused by radio-frequency sources.
Examples can include:
transmitters;
certain wireless equipment.
Avoid unnecessarily routing sensitive or high-speed copper cabling near strong interference sources.
Fiber carries information using light rather than electrical signaling.
Fiber commonly supports:
high bandwidth;
long distances;
resistance to electromagnetic interference.
Because fiber does not normally radiate electrical signals like copper, certain forms of electromagnetic interception are reduced.
A critical exam point:
More difficult to intercept does not mean impossible to intercept.
Physical access and specialized tapping techniques can still create risk.
Attenuation is the reduction in signal strength as a signal travels through a transmission medium.
STRONG SIGNAL
β
βΌ
ββββββββββββββ CABLE ββββββββββββββ
β
βΌ
WEAKER SIGNAL
Excessive signal loss can cause:
errors;
retransmission;
reduced performance;
connectivity failure.
Signal quality affects:
reliability;
throughput;
availability.
Security architecture must consider whether the communication medium can reliably support the mission.
Examples:
attenuation;
interference;
physical damage;
distance;
connector quality.
Communication cabling may traverse:
ceilings;
floors;
conduits;
closets;
public areas.
Sensitive cable routes may require:
conduit;
locked wiring closets;
secure building pathways;
inspection;
tamper evidence.
An attacker does not need to decrypt information if the objective is:
deny service.
Physical cable protection supports availability.
Wireless communication uses radio-frequency or similar propagation instead of a physical conductor.
NIST notes that WLAN security depends on securing wireless components throughout design, deployment, maintenance, and monitoring.
A cable terminates at physical locations.
Wireless signals may pass:
through walls;
into parking areas;
into neighboring spaces.
ββββββββββββββββββββββββ
β OFFICE BUILDING β
β ACCESS POINT β
β ))) β
βββββββββββ)))ββββββββββ
)))
PARKING AREA
Attackers may attempt to connect from outside the organization's physical perimeter.
Consider:
encryption;
authentication;
access-point placement;
transmit power;
rogue-AP detection;
guest segmentation.
Network Access Control determines whether a user or device should be permitted to connect to or remain connected to a network.
NIST's glossary describes NAC as controlling access based on credentials and, in some implementations, client-device health checks.
Instead of asking only:
Is there an Ethernet cable connected?
NAC asks:
Who or what is connecting, and should it receive network access?
DEVICE CONNECTS
β
βΌ
IDENTIFY / AUTHENTICATE
β
βΌ
CHECK POLICY / POSTURE
β
βββββ΄βββββββββββββ
βΌ βΌ
COMPLIANT NONCOMPLIANT
β β
βΌ βΌ
ALLOW RESTRICT /
QUARANTINE
Pre-admission NAC evaluates the endpoint:
before normal access is granted.
Possible checks include:
authentication;
device identity;
security posture.
LAPTOP CONNECTS
β
βΌ
MFA/DEVICE AUTH
β
βΌ
PATCH STATUS?
β
βΌ
EDR RUNNING?
β
βΌ
COMPLIANT?
β
βΌ
PRODUCTION NETWORK
Post-admission NAC continues evaluating activity after the device has joined.
If conditions change, access can be:
restricted;
terminated;
moved to quarantine.
A device might be compliant at 9:00 AM and compromised at 2:00 PM.
Trust should not necessarily be permanent.
802.1X provides port-based network access-control concepts for wired and wireless networks.
NIST implementation guidance describes 802.1X as a mechanism for authenticating an endpoint to a network device, with the network device forwarding authentication requests to a supporting authentication infrastructure.
Remember:
SUPPLICANT
β
βΌ
AUTHENTICATOR
β
βΌ
AUTHENTICATION SERVER
The supplicant is:
the endpoint requesting network access.
Example:
laptop;
workstation.
The authenticator controls the network access point.
Examples:
Ethernet switch;
wireless access point.
The authentication server validates authentication information and supports the network-access decision.
RADIUS is commonly used for this role.
LAPTOP
Supplicant
β
βΌ
SWITCH
Authenticator
β
βΌ
RADIUS
Authentication Server
β
βΌ
ALLOW / DENY
Remote Authentication Dial-In User Service is widely used to centralize AAA-related functions for network access.
Conceptually:
ACCESS DEVICE
β
βΌ
RADIUS SERVER
β
βββ Authenticate
βββ Authorize
βββ Account
Detailed AAA and RADIUS concepts will be expanded in Domain 5.
Endpoint posture is the device's security condition.
Possible checks include:
approved operating system;
patch level;
EDR status;
firewall status;
disk encryption;
device management.
A user can be legitimate while the device is dangerous.
Example:
AUTHORIZED USER
+
COMPROMISED LAPTOP
=
NETWORK RISK
Therefore modern admission decisions may consider both.
A noncompliant endpoint may be placed in a restricted network.
NONCOMPLIANT DEVICE
β
βΌ
QUARANTINE VLAN
β
βββ Patch server
βββ EDR remediation
βββ Limited support
Quarantine allows remediation without giving the device unrestricted production access.
DEVICE FAILS POSTURE
β
βΌ
QUARANTINE
β
βΌ
UPDATE / CLEAN / CONFIGURE
β
βΌ
REASSESS
β
βββββ΄ββββ
PASS FAIL
β β
ALLOW REMAIN
Visitors may need Internet access.
They generally should not automatically obtain:
production-server access;
management-plane access;
internal business-system access.
GUEST DEVICE
β
βΌ
GUEST NETWORK
β
βΌ
INTERNET
X
INTERNAL SENSITIVE NETWORK
BYOD permits personally owned devices to access organizational services.
Risk arises because the organization may have less control over:
configuration;
patching;
applications;
storage.
Possible approaches include:
NAC;
MDM/UEM;
containerization;
application-level access;
Zero Trust access;
separate networks.
A software agent on an endpoint may collect detailed security information.
Advantages:
rich posture visibility.
Challenges:
deployment;
maintenance;
privacy;
device compatibility.
Agentless solutions assess devices without installing a permanent endpoint agent.
Advantages:
easier coverage in some environments.
Limitations:
potentially less detailed posture information.
Some environments identify endpoints by MAC address.
But:
MAC addresses can be observed or spoofed.
Therefore MAC-based identification should not be considered equivalent to strong cryptographic identity.
Choose the strength of network admission control based on:
asset value;
device type;
risk.
The current outline explicitly identifies:
physical and virtual NAC solutions.
Virtual environments may enforce admission or segmentation using:
virtual switches;
cloud policy;
software-defined controls;
identity-aware policies.
Endpoints include:
workstations;
laptops;
servers;
mobile devices;
virtual machines.
The official objective specifically includes endpoint security, such as host-based security.
The network may be secure.
But if an authorized endpoint is compromised:
ATTACKER
β
βΌ
COMPROMISED AUTHORIZED DEVICE
β
βΌ
LEGITIMATE NETWORK CONNECTION
β
βΌ
INTERNAL RESOURCES
Network security and endpoint security must complement each other.
PATCHING
β
βΌ
HOST FIREWALL
β
βΌ
ANTI-MALWARE / EDR
β
βΌ
APPLICATION CONTROL
β
βΌ
DISK ENCRYPTION
β
βΌ
LEAST PRIVILEGE
β
βΌ
LOGGING / MONITORING
A host firewall applies network policy directly to an endpoint.
Benefit:
protection travels with the device.
A laptop leaves the protected office LAN and joins hotel Wi-Fi.
The enterprise perimeter firewall no longer surrounds the device.
A properly configured host firewall still provides local network filtering.
Anti-malware tools attempt to detect and prevent malicious software.
They may use:
signatures;
heuristics;
behavior analysis.
No anti-malware product detects every threat.
Use defense in depth.
Endpoint Detection and Response provides endpoint monitoring, detection, investigation, and response capabilities.
ENDPOINT ACTIVITY
β
βΌ
TELEMETRY
β
βΌ
DETECTION / ANALYTICS
β
βΌ
ALERT
β
βΌ
INVESTIGATION
β
βΌ
RESPONSE
Depending on architecture, EDR may:
isolate a host;
terminate a process;
collect evidence;
support investigation.
A HIDS monitors a host for suspicious activity.
Sources can include:
logs;
files;
system events;
integrity changes.
A HIPS can attempt to actively prevent certain malicious host behaviors.
Again:
HIDS = Detect
HIPS = Detect + Prevent
Application allowlisting permits approved software to execute while blocking unauthorized software.
Blocklist:
Block known bad applications.
Allowlist:
Permit approved applications.
Allowlisting can provide stronger control in stable, tightly managed environments.
Disk encryption protects stored information if a device is:
lost;
stolen.
It primarily protects:
Disk encryption does not automatically protect data when:
the device is unlocked;
malware runs under an authorized session.
Endpoints should receive appropriate:
operating-system updates;
application updates;
firmware updates.
DISCOVER UPDATE
β
βΌ
ASSESS
β
βΌ
TEST
β
βΌ
DEPLOY
β
βΌ
VERIFY
Hardening reduces unnecessary attack surface.
Examples:
disable unused services;
remove unnecessary software;
restrict administrative rights;
enable security features.
A managed endpoint should start from:
a secure approved baseline
rather than from an unrestricted consumer configuration.
Users with permanent local administrator rights can:
install software;
modify controls;
disable protections.
Where feasible, users should operate with only the privilege required for their role.
Endpoints can generate security information including:
authentication events;
process execution;
malware detection;
configuration changes.
ENDPOINTS
β β β
βΌ βΌ βΌ
CENTRAL LOGGING / SIEM
β
βΌ
ANALYSIS
β
βΌ
RESPONSE
MDM can enforce security controls on:
smartphones;
tablets.
Possible controls include:
encryption;
screen lock;
application policy;
remote wipe.
UEM extends centralized endpoint-management concepts across broader device types.
When a host is compromised:
ENDPOINT
β
βΌ
EDR / NAC DECISION
β
βΌ
ISOLATE
β
βΌ
INVESTIGATE
β
βΌ
REMEDIATE
This demonstrates how NAC and endpoint security can work together.
Modern security can combine:
user identity;
device identity;
posture;
behavior;
network policy.
USER
+
DEVICE
+
POSTURE
+
CONTEXT
β
βΌ
ACCESS DECISION
This aligns with modern enterprise architectures that move beyond simple perimeter-based trust. NIST's secure enterprise-network guidance specifically discusses device/endpoint security, cloud access, micro-segmentation, and Zero Trust-related frameworks as integrated concerns.
Network logs may include:
administrator login;
configuration change;
interface state;
denied traffic;
routing events.
Example:
FIREWALL RULE CHANGED
β
βΌ
LOG GENERATED
β
βΌ
SIEM
β
βΌ
AUTHORIZED CHANGE?
βββββ΄βββββ
YES NO
β β
CLOSE INVESTIGATE
Network infrastructure should use appropriate trusted time synchronization.
Without consistent timestamps:
log correlation becomes difficult;
investigations become harder.
SNMP supports monitoring and management of network devices.
Older versions have weaker security characteristics.
For sensitive management, use:
appropriately secured modern configurations rather than legacy insecure settings.
SNMPv3 can provide security capabilities such as:
authentication;
integrity;
privacy/encryption
depending on configuration.
Do not expose powerful network-management protocols broadly to untrusted networks.
INTERNET
β
βΌ
EDGE ROUTERS
A B
\ /
\ /
FIREWALL HA
β
βΌ
DMZ
β
βΌ
INTERNAL FIREWALL
β
βββββββββββββββββΌβββββββββββββββ
βΌ βΌ βΌ
USERS SERVERS ADMIN
β β β
βΌ βΌ βΌ
NAC HOST SECURITY MGMT NETWORK
β β β
βββββββββββββββββ¬β΄βββββββββββββββ
βΌ
SIEM / MONITORING
Supporting controls include:
redundant power;
supported firmware;
configuration backups;
endpoint posture checks;
secure administrative access.
Use the SierraTec Secure HARDNET model for network-component questions.
Remove defaults and unnecessary services.
Use redundancy, supported hardware, power, and failover.
Protect privileged management interfaces.
Protect media and signal quality.
Authenticate and evaluate devices before granting access.
Use layered host security.
Monitor infrastructure and test controls.
H
HARDEN
β
βΌ
A
ASSURE AVAILABILITY
β
βΌ
R
RESTRICT ADMINISTRATION
β
βΌ
D
DEFEND TRANSMISSION
β
βΌ
N
NETWORK ADMISSION
β
βΌ
E
ENDPOINT PROTECTION
β
βΌ
T
TELEMETRY & TEST
A core switch has two power supplies, but both are plugged into the same nonredundant power strip.
What is the GREATEST concern?
A. Common-mode failure.
B. Excessive authentication.
C. Too much encryption.
D. VLAN hopping.
A
The duplicate power supplies do not remove the shared power-strip dependency.
A critical firewall works correctly but has reached End of Support.
What should management do?
A. Assess risk and plan replacement or an appropriately governed mitigation.
B. Assume it is secure because traffic still passes.
C. Disable backups.
D. Ignore future vulnerability disclosures.
A
An organization purchases a standby router but never tests failover.
What is the PRIMARY concern?
A. The organization does not have assurance that redundancy will work when required.
B. The router is automatically insecure.
C. The standby router needs no configuration.
D. Testing would reduce availability permanently.
A
Network-device management interfaces are accessible from every employee VLAN.
What is the BEST improvement?
A. Restrict administrative access through a dedicated protected management path.
B. Enable Telnet.
C. Remove authentication.
D. Publish the configuration.
A
A firewall permits only return traffic associated with previously established connections.
Which capability is MOST relevant?
A. Stateful inspection.
B. Data masking.
C. Tokenization.
D. Physical redundancy.
A
A security device monitors network traffic and sends alerts but does not sit inline.
Which technology BEST matches?
A. IDS.
B. IPS.
C. Load balancer.
D. Router only.
A
A security appliance detects a known exploit and automatically drops the offending packets.
Which technology is MOST directly represented?
A. IPS.
B. Passive IDS only.
C. Hub.
D. UPS.
A
An organization requires high-bandwidth communication across a facility containing significant electromagnetic interference.
Which medium is generally preferable?
A. Fiber-optic cabling.
B. Unshielded copper beside high-power motors.
C. Open wireless only.
D. Telephone cord.
A
A long cable run experiences progressively weaker signal levels and increased errors.
Which concept BEST describes the issue?
A. Attenuation.
B. Authentication.
C. Hash collision.
D. Revocation.
A
A laptop connects to an internal switch. Before receiving production access, the organization checks its device identity, patch level, and EDR status.
Which control is MOST directly involved?
A. NAC.
B. CDN.
C. Data masking.
D. PKI only.
A
A workstation requests access through a switch.
What is the workstation called in 802.1X terminology?
A. Supplicant.
B. Authenticator.
C. Authentication server.
D. Proxy.
A
In an 802.1X deployment, which component normally controls whether the endpoint's network port is authorized?
A. Switch or wireless access point acting as authenticator.
B. End-user document.
C. Backup server.
D. HSM.
A
A device authenticates successfully but lacks required security updates.
What should a risk-based NAC system BEST do?
A. Place the device in restricted remediation access rather than grant full production access.
B. Grant unrestricted access because the username was valid.
C. Disable all network controls.
D. Give the user administrative rights.
A
An organization relies solely on MAC addresses to authenticate high-risk administrative workstations.
What is the PRIMARY concern?
A. MAC addresses can be spoofed and are not strong identity proof.
B. MAC addresses are encrypted automatically.
C. MAC addresses are certificates.
D. MAC addresses are impossible to observe.
A
A corporate laptop is frequently used on hotel networks.
Which control provides endpoint-level network filtering regardless of the local perimeter?
A. Host firewall.
B. Data-center firewall only.
C. Network hub.
D. Load balancer.
A
An employee laptop containing sensitive information is stolen.
Which endpoint control MOST directly protects the confidentiality of stored information when properly configured?
A. Full-disk encryption.
B. Network IDS only.
C. Load balancing.
D. VLAN tagging.
A
Security operations needs detailed endpoint process activity and the ability to isolate infected systems.
Which technology BEST fits?
A. EDR.
B. Passive network hub.
C. Generator.
D. RAID.
A
A kiosk should execute only a small approved set of applications.
Which approach BEST fits?
A. Application allowlisting.
B. Allow every executable.
C. Disable endpoint controls.
D. Provide permanent administrator rights.
A
Personally owned devices require access to email but should not receive unrestricted connectivity to sensitive internal systems.
Which approach is BEST?
A. Apply risk-based access controls such as managed application access, NAC, segmentation, and device policy.
B. Place all BYOD devices directly on the server-management network.
C. Remove authentication.
D. Share administrator credentials.
A
Architecture requires securely operated components to enforce it.
Shared dependencies can defeat both.
Look for common-mode failure.
Hardware replacement and vendor support directly affect operational availability.
A device can operate normally after vendor security support ends.
The risk still increases.
Network devices rely on firmware and operating-system code that can contain vulnerabilities.
A firewall controls traffic according to policy.
It does not replace:
endpoint security;
identity;
patching;
monitoring.
IDS primarily detects.
IPS may actively prevent.
Fiber can be more resistant to some interception techniques but is not invulnerable.
NAC may consider:
identity;
device security posture;
context.
A legitimate user can operate a compromised endpoint.
MAC addresses can be spoofed.
Post-admission monitoring can reassess endpoints after initial admission.
A quarantine network may permit limited remediation services while denying production resources.
Modern endpoint security can include:
firewall;
EDR;
patching;
encryption;
application control;
hardening.
Disk encryption primarily protects stored data when the device is not properly unlocked by an attacker.
It does not replace runtime endpoint security.
Shared privileged accounts reduce accountability and increase security risk.
Which issue is explicitly included in CISSP Domain 4.2 infrastructure operations?
A. Redundant power.
B. Copyright.
C. Data classification only.
D. Software patents.
A
Why are vendor warranties relevant to network security?
A. They can affect timely hardware replacement and service availability.
B. They provide encryption.
C. They replace firewalls.
D. They authenticate users.
A
What is a common-mode failure?
A. A single condition capable of defeating multiple redundant components.
B. Successful device failover.
C. Strong endpoint encryption.
D. VLAN separation.
A
What is a secure configuration baseline?
A. Approved reference configuration for a device.
B. Password shared by all administrators.
C. Unrestricted default configuration.
D. Warranty certificate.
A
Which network component primarily controls traffic between security zones according to policy?
A. Firewall.
B. UPS.
C. Fiber cable.
D. HSM.
A
What does a stateful firewall track?
A. Connection state.
B. Humidity.
C. Physical badges.
D. Disk sectors.
A
Which technology primarily alerts on suspicious traffic without necessarily blocking it?
A. IDS.
B. IPS only.
C. UPS.
D. Router warranty.
A
Which technology can be placed inline to block detected attacks?
A. IPS.
B. Passive IDS only.
C. Network tap.
D. Patch panel.
A
Which medium is inherently resistant to electromagnetic interference?
A. Fiber.
B. Unshielded copper.
C. Coax only.
D. Radio.
A
What is attenuation?
A. Loss of signal strength over distance.
B. User authentication.
C. Firewall rule removal.
D. Device revocation.
A
What is crosstalk?
A. Unwanted signal coupling between communication paths.
B. Secure authentication.
C. Network redundancy.
D. Load balancing.
A
What is the primary purpose of NAC?
A. Control which devices/users receive network access.
B. Replace routing.
C. Create backups.
D. Encrypt every file.
A
In 802.1X, what is the endpoint requesting access called?
A. Supplicant.
B. Authenticator.
C. Authentication server.
D. Relying party.
A
In 802.1X, what commonly acts as the authenticator?
A. Switch or access point.
B. Certificate Authority.
C. User's document.
D. Backup tape.
A
What does endpoint posture represent?
A. Security condition of the endpoint.
B. Physical sitting position of a user.
C. Network topology.
D. Warranty status only.
A
Why might a device be placed on a quarantine network?
A. It is noncompliant and requires remediation.
B. It has perfect security.
C. It requires unrestricted database access.
D. It is a router.
A
Which endpoint control can continue filtering network traffic when a laptop leaves the corporate network?
A. Host firewall.
B. Corporate perimeter firewall alone.
C. Data-center load balancer.
D. UPS.
A
Which technology provides endpoint telemetry, investigation, and response capability?
A. EDR.
B. Cable conduit.
C. VLAN.
D. Generator.
A
What does application allowlisting do?
A. Restricts execution to approved applications.
B. Allows every application except known malware.
C. Encrypts network traffic.
D. Replaces patching.
A
Which statement is MOST accurate?
A. Network and endpoint security should operate as complementary layers.
B. Endpoint security makes segmentation unnecessary.
C. NAC replaces authentication.
D. Fiber eliminates every physical threat.
A
A company's two Internet routers use different carriers but both carrier circuits enter the building through the same underground conduit.
What is the GREATEST concern?
A. Physical common-mode failure.
B. Too much redundancy.
C. Lack of endpoint encryption.
D. DNS caching.
A
A core firewall has not received firmware security updates because the organization's support contract expired.
What is the BEST action?
A. Assess the risk and restore supported maintenance or migrate to supported infrastructure.
B. Ignore the issue if traffic still flows.
C. Disable firewall logging.
D. Publish the configuration.
A
A temporary firewall rule was added six months ago and no one can determine whether it is still needed.
What process should address this?
A. Configuration and rule lifecycle review.
B. Data destruction.
C. Password hashing.
D. Physical media disposal.
A
A security team wants visibility into traffic traversing a switch without placing the monitoring device inline.
Which technique is MOST directly applicable?
A. Port mirroring/SPAN or an appropriate network tap.
B. UPS.
C. Disk encryption.
D. RAID.
A
A laptop presents valid user credentials but its endpoint security software is disabled.
What should a mature NAC design consider?
A. Restricting access based on both identity and endpoint posture.
B. Granting unrestricted access because authentication succeeded.
C. Removing all endpoint controls.
D. Publishing the device MAC address.
A
A network switch authenticates devices through an external RADIUS service before allowing production connectivity.
Which general technology is being implemented?
A. 802.1X/NAC.
B. CDN.
C. IPsec tunnel only.
D. File encryption.
A
A compromised endpoint is automatically moved from the production VLAN into a restricted remediation segment.
Which controls are working together?
A. Endpoint detection and NAC.
B. Generator and UPS only.
C. RAID and load balancing.
D. PKI and copyright.
A
A company uses full-disk encryption but does not patch its laptops or deploy endpoint detection.
Which statement is BEST?
A. Data-at-rest protection exists, but runtime endpoint compromise remains a significant risk.
B. Full-disk encryption eliminates malware risk.
C. Patch management is no longer necessary.
D. Network access controls are unnecessary.
A
A data center's copper network cables run next to large electrical motors and experience intermittent communication errors.
Which problem is MOST likely?
A. Electromagnetic interference.
B. Certificate revocation.
C. Tailgating.
D. Hash collision.
A
An organization is replacing network switches. One product is cheaper, but vendor support will end in 12 months. Another has several years of support remaining.
Which factor should security leadership consider MOST?
A. Total lifecycle and support risk, not purchase price alone.
B. Choose the cheaper device regardless of support.
C. Warranty and support are unrelated to cybersecurity.
D. Switches do not require security patches.
A
| Concept | Think |
|---|---|
| Redundant power | Avoid single power failure |
| HA pair | Survive device failure |
| Failover | Transfer service to standby |
| Warranty | Hardware replacement capability |
| Vendor support | Patches and technical assistance |
| End of Support | Increasing lifecycle risk |
| Firmware | Embedded software requiring updates |
| Baseline | Approved device configuration |
| Configuration backup | Recover network function |
| Management plane | High-value administrative access |
| Component | Primary Role |
|---|---|
| Router | Forward traffic between IP networks |
| Switch | Forward Layer 2 frames |
| Firewall | Enforce traffic policy |
| Proxy | Intermediary for communication |
| Reverse proxy | Protect/front backend servers |
| Load balancer | Distribute workload |
| IDS | Detect and alert |
| IPS | Detect and potentially block |
| Network tap | Provide monitoring visibility |
| NAC | Control network admission |
| Media | Key Characteristics |
|---|---|
| Copper | Electrical signals; EMI/RFI concerns |
| Fiber | Light; high bandwidth; EMI resistant |
| Wireless | RF propagation beyond physical walls |
| Twisted pair | Twisting helps reduce interference/crosstalk |
| Role | Think |
|---|---|
| Supplicant | Endpoint requesting access |
| Authenticator | Switch/AP controlling access |
| Authentication Server | Validates access request |
| RADIUS | Common centralized AAA service |
| Posture Check | Is device compliant? |
| Quarantine | Restricted remediation environment |
| Control | Purpose |
|---|---|
| Host firewall | Local network filtering |
| Anti-malware | Detect known/suspicious malware |
| EDR | Detect, investigate, respond |
| HIDS | Host intrusion detection |
| HIPS | Host intrusion prevention |
| Disk encryption | Protect data at rest |
| Allowlisting | Restrict software execution |
| Patching | Correct vulnerabilities |
| MDM/UEM | Centralized device management |
| NAC integration | Restrict network access by posture |
Processes necessary to keep network infrastructure secure, available, supported, and maintainable.
Additional component or path intended to preserve service after failure.
Single event capable of defeating multiple redundant components.
Transfer of operations to a backup component.
Architecture intended to maintain service despite component failures.
Point at which normal vendor security and technical support ends.
Software embedded within hardware devices.
Approved reference configuration.
Deviation from approved configuration over time.
Device or software controlling network traffic according to policy.
Firewall capability tracking network connection state.
Intermediary communicating on behalf of another system.
Proxy positioned in front of server resources.
Component distributing connections or requests among resources.
Intrusion Detection System.
Intrusion Prevention System.
Detection based on known threat patterns.
Detection based on deviations from expected behavior.
Mechanism for providing monitoring access to network traffic.
Switch-port mirroring capability used for traffic monitoring.
Physical or wireless mechanisms carrying network signals.
Electrical transmission medium.
Light-based transmission medium.
Loss of signal strength over distance.
Electromagnetic Interference.
Radio-Frequency Interference.
Unwanted signal coupling between communication paths.
Network Access Control.
Assessment performed before production network access.
Assessment and control after network admission.
Port-based network-access control framework.
Endpoint requesting 802.1X network access.
Network device controlling access in 802.1X.
System validating network-access credentials or policy.
Centralized Authentication, Authorization, and Accounting protocol commonly used with network access.
Evaluation of endpoint security condition.
Restricted environment used for noncompliant endpoints.
Security controls applied directly to endpoint devices.
Firewall operating on an individual endpoint.
Endpoint Detection and Response.
Host-Based Intrusion Detection System.
Host-Based Intrusion Prevention System.
Policy permitting only approved executable software.
Mobile Device Management.
Unified Endpoint Management.
Use this sequence:
NETWORK COMPONENT
β
βΌ
IS IT SUPPORTED?
β
βΌ
IS IT HARDENED?
β
βΌ
IS MANAGEMENT RESTRICTED?
β
βΌ
IS IT REDUNDANT?
β
βΌ
IS TRAFFIC / MEDIA PROTECTED?
β
βΌ
ARE DEVICES VERIFIED BEFORE ACCESS?
β
βΌ
ARE ENDPOINTS PROTECTED?
β
βΌ
IS EVERYTHING MONITORED?
For CISSP questions:
Domain 4.2 currently centers on infrastructure operations, transmission media, NAC, and endpoint security.
Redundant components should not share avoidable common failure points.
Redundant power should use meaningful independent power paths where required.
High-availability systems must be tested.
Hardware warranty and vendor support affect availability and security.
A working unsupported network device can still represent unacceptable risk.
Network-device firmware requires lifecycle management.
Baselines help identify configuration drift.
Protect configuration backups.
Management interfaces are high-value targets.
Separate privileged management from ordinary user access.
Use secure management protocols.
Routers and switches should follow hardened approved configurations.
Firewalls enforce communication policy but do not replace endpoint security.
Stateful firewalls understand connection state.
IDS primarily detects.
IPS may block.
Monitoring requires visibility into relevant traffic.
Copper may be affected by EMI, RFI, attenuation, and crosstalk.
Fiber is resistant to EMI but is not impossible to tap.
Wireless signals can extend beyond physical facility boundaries.
NAC decides whether a user/device should receive network access.
NIST describes NAC in terms of credentials and, where applicable, client health checks.
In 802.1X, remember supplicant β authenticator β authentication server. NIST deployment guidance describes 802.1X authentication of endpoints through network devices with authentication forwarded to supporting infrastructure.
Successful user authentication does not guarantee a safe endpoint.
Posture checks can consider device security state.
Noncompliant endpoints can be quarantined.
MAC-address identification is weaker than robust authentication.
Endpoint security is broader than antivirus.
Host firewalls remain important outside the enterprise perimeter.
EDR improves endpoint detection, investigation, and response.
Full-disk encryption protects data at rest, not all runtime activity.
Application allowlisting can restrict unauthorized execution.
NAC and endpoint security can work together for continuous access decisions.
Network infrastructure should be monitored for configuration and operational changes.
Lesson Fifteen focused on securing the network components that implement the architecture introduced in Lesson Fourteen.
The current CISSP Objective 4.2 defines four major areas:
INFRASTRUCTURE OPERATIONS
β
TRANSMISSION MEDIA
β
NETWORK ACCESS CONTROL
β
ENDPOINT SECURITY
You learned that infrastructure security includes more than configuring routers and switches.
A critical device must be:
SUPPORTED
+
PATCHED
+
HARDENED
+
REDUNDANT
+
MONITORED
=
TRUSTWORTHY INFRASTRUCTURE
You examined availability engineering through:
device redundancy;
power redundancy;
link redundancy;
failover;
warranty;
vendor support.
You learned that redundant architecture must consider common-mode failures.
REDUNDANT DEVICE A
+
REDUNDANT DEVICE B
+
SAME SINGLE FAILURE POINT
=
NOT TRUE RESILIENCE
You examined network-security components including:
routers;
switches;
firewalls;
proxies;
load balancers;
IDS;
IPS;
traffic-monitoring mechanisms.
NIST describes firewalls as components that control network traffic between networks or systems with differing security postures and emphasizes proper policy, configuration, deployment, testing, and management.
You then studied transmission media.
COPPER
β
βββ EMI
βββ RFI
βββ Crosstalk
βββ Attenuation
FIBER
β
βββ Light
βββ High bandwidth
βββ EMI resistant
βββ Still physically protect
WIRELESS
β
βββ Signals may cross facility boundaries
The official CISSP objective specifically requires candidates to understand both the physical security of transmission media and signal-propagation quality.
The lesson then introduced Network Access Control.
DEVICE CONNECTS
β
AUTHENTICATE
β
ASSESS POSTURE
β
APPLY POLICY
β
ALLOW / RESTRICT / QUARANTINE
NIST recognizes NAC as a mechanism that can consider both credentials and device health when making access decisions.
For 802.1X, remember:
SUPPLICANT
β
AUTHENTICATOR
β
AUTHENTICATION SERVER
Finally, you studied endpoint security as a critical network-control layer:
PATCHING
β
HOST FIREWALL
β
ANTI-MALWARE / EDR
β
APPLICATION CONTROL
β
DISK ENCRYPTION
β
LEAST PRIVILEGE
β
MONITORING
NIST's modern enterprise-network guidance similarly recognizes endpoint/device security as part of the broader enterprise network-security environment alongside micro-segmentation, cloud access, VPNs, SASE, and Zero Trust-related approaches.
The central Lesson Fifteen principle is:
A secure network is not created simply by designing the correct topology. Every device, management interface, transmission path, endpoint, and network-access decision must remain hardened, supported, monitored, appropriately redundant, and governed throughout its operational lifecycle.
Before continuing to Lesson Sixteen, make sure you can explain:
The four current CISSP Domain 4.2 categories.
Why network-component security differs from network architecture.
Why infrastructure availability is part of security.
What redundancy means.
What common-mode failure means.
Why dual power supplies may still share a single failure point.
What active/passive and active/active mean conceptually.
What failover means.
Why failover must be tested.
Why warranty matters to security.
Why vendor support matters.
Why End of Support creates risk.
Why network-device firmware requires patching.
What a network-device security baseline is.
What configuration drift means.
Why configuration backups require protection.
Why management interfaces are high-value targets.
Why dedicated management networks improve security.
Why administrator actions should be attributable.
What AAA means.
What routers do.
What switches do.
What firewalls do.
What packet filtering means.
What stateful inspection means.
What an application-aware firewall does conceptually.
What a forward proxy does.
What a reverse proxy does.
What a load balancer does.
Why a load balancer can become a single point of failure.
The difference between IDS and IPS.
The difference between signature and anomaly detection.
Why monitoring tools need traffic visibility.
What a network tap does.
What SPAN/port mirroring does.
Why monitored traffic itself may be sensitive.
The differences among copper, fiber, and wireless media.
What attenuation means.
What EMI means.
What RFI means.
What crosstalk means.
Why fiber is resistant to EMI.
Why fiber is not impossible to intercept.
Why wireless extends the network's effective physical exposure.
What NAC does.
What pre-admission NAC means.
What post-admission NAC means.
What 802.1X does.
What a supplicant is.
What an authenticator is.
What an authentication server is.
How RADIUS supports NAC.
What endpoint posture means.
Why valid credentials alone may be insufficient.
What a quarantine network does.
How guest networks should be separated.
Why BYOD needs special controls.
The difference between agent-based and agentless NAC.
Why MAC addresses are weak authentication identifiers.
What endpoint security means.
What a host firewall does.
What EDR does.
The difference between HIDS and HIPS.
What application allowlisting does.
What full-disk encryption protects.
Why disk encryption does not stop runtime malware.
Why endpoint patching matters.
What MDM and UEM do.
How NAC and endpoint security can integrate.
Why endpoint and network telemetry should be centrally monitored.
Lesson Sixteen will address CISSP Domain 4.3 β Implement secure communication channels according to design.
The current outline explicitly includes:
voice, video, and collaboration technologies;
conferencing and collaboration rooms;
remote access;
network administrative functions;
data communications;
backhaul networks;
satellite communications;
third-party connectivity;
telecommunications providers;
hardware-support connectivity.
Lesson Sixteen will therefore cover:
secure remote access architecture;
VPNs;
client VPN;
site-to-site VPN;
IPsec;
TLS VPNs;
remote desktop;
RDP security;
SSH;
bastion hosts;
jump servers;
privileged access workstations;
remote administrative access;
split tunneling;
full tunneling;
remote-access MFA;
endpoint posture;
Zero Trust Network Access;
voice security;
VoIP;
SIP concepts;
secure voice;
video conferencing;
collaboration platforms;
meeting-room security;
screen sharing;
recording controls;
data communication;
private circuits;
MPLS concepts;
backhaul networks;
satellite communication;
telecom-provider risk;
partner connectivity;
vendor remote support;
third-party VPN access;
restricted vendor accounts;
time-limited access;
monitoring of remote sessions;
third-party connection termination;
original secure-channel architecture diagrams;
scenario-based CISSP questions.
The central Lesson Sixteen question will be:
How should remote users, administrators, business partners, communications platforms, carriers, and third-party support providers connect to organizational resources without weakening identity, segmentation, confidentiality, monitoring, or least-privilege requirements?
This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.
CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.
The current examination alignment was verified against the ISC2 CISSP Certification Exam Outline. Domain 4.2 currently identifies infrastructure operations, transmission-media protection and propagation quality, physical/virtual Network Access Control, and host-based endpoint security.
Supporting firewall concepts were aligned with NIST SP 800-41 Rev. 1, which describes firewalls as controlling network traffic between systems or networks with differing security postures.
NAC terminology was supplemented by NIST definitions and practice guidance. NIST describes NAC as controlling network access based on credentials and, in applicable implementations, device-health information; NIST implementation material also identifies 802.1X as a mechanism for authenticating endpoints through network devices to supporting authentication infrastructure.
Wireless infrastructure concepts were supplemented by NIST SP 800-153, which emphasizes securing wireless clients, access points, and switching components throughout the WLAN lifecycle.
The SierraTec Secure HARDNET model, diagrams, comparison tables, scenarios, knowledge checks, and practice questions are original educational material and are not actual, recalled, leaked, or official CISSP examination questions.