4.1 Secure Network Architecture

CISSP Domain 4 ยท Communication and Network Security

4.1 Secure Network Architecture

Secure network architecture determines how systems communicate, where trust boundaries exist and how traffic is separated, protected, routed and monitored.

For CISSP, the goal is not simply to memorise network technologies. You need to understand how architecture decisions affect confidentiality, integrity, availability and the ability of an attacker to move through an environment.

๐ŸŒ

Connect

Understand how systems communicate through layered network architectures.

PROTOCOLS & FLOWS
๐Ÿงฑ

Separate

Divide networks and workloads according to trust and business need.

SEGMENTATION
๐Ÿ‘๏ธ

Observe

Understand network behaviour and identify abnormal or dangerous activity.

VISIBILITY

The Big Idea

A secure network should not allow every connected system to communicate freely with every other system.

Architecture should determine:

๐Ÿ“ Location โ†’ Where is the system?
๐Ÿ‘ค Identity โ†’ Who or what is communicating?
โžก๏ธ Flow โ†’ Where should traffic be allowed to go?
๐Ÿ” Protection โ†’ How should communication be protected?
๐Ÿงฑ Boundary โ†’ Where should trust change?
๐Ÿ‘๏ธ Monitoring โ†’ Can suspicious traffic be detected?

Secure Network Architecture

CONNECT Only what needs communication
SEGMENT Separate different trust levels
PROTECT Secure important traffic
CONTROL Limit permitted flows
OBSERVE Understand what is happening

Connect ยท Segment ยท Protect ยท Control ยท Observe

CISSP 4.1 Scope

What You Need to Understand

OSI & TCP/IP

How network communication is divided into layers.

IPv4 & IPv6

Addressing and delivery models.

Secure Protocols

IPsec, SSH and TLS.

Multilayer Protocols

Encapsulation and security across protocol layers.

Converged Protocols

Different types of traffic sharing infrastructure.

Transport Architecture

Topology, network planes and forwarding behaviour.

Performance

Bandwidth, throughput, latency, jitter and signal quality.

Traffic Flows

North-south and east-west communication.

Physical Segmentation

Separate infrastructure, out-of-band and air gaps.

Logical Segmentation

VLANs, VPNs, VRFs and virtual domains.

Microsegmentation

Fine-grained workload and service isolation.

Edge Networks

Ingress, egress and peering.

Wireless

Wi-Fi, Bluetooth, Zigbee and satellite.

Cellular

4G and 5G architectures.

CDN

Distributed delivery of content closer to users.

SDN / SD-WAN / NFV

Software-controlled and virtualised networking.

Virtual Private Cloud

Logically isolated cloud networking.

Network Management

Observability, traffic management, capacity and fault handling.

๐Ÿงฑ The OSI Model Seven layers for understanding network communication

The Open Systems Interconnection model divides network communication into seven conceptual layers.

For CISSP, it is useful because security controls and attacks often operate at different layers.

LayerNameMain RoleExamples / Concepts
7ApplicationServices used by applicationsHTTP, DNS, SMTP
6PresentationData representation, encoding, encryption conceptsFormatting, compression, encoding
5SessionEstablish and manage communication sessionsSession establishment and coordination
4TransportEnd-to-end transportTCP, UDP, ports
3NetworkLogical addressing and routingIPv4, IPv6, routers
2Data LinkLocal network deliveryEthernet, MAC addresses, switches, VLANs
1PhysicalTransmission of signalsCopper, fibre, radio

OSI Layers - Top to Bottom

7 APPLICATION User-facing network services
6 PRESENTATION Representation
5 SESSION Conversation
4 TRANSPORT End-to-end delivery
3 NETWORK Routing
2 DATA LINK Local frames
1 PHYSICAL Signals and media
CISSP perspective

The OSI model is primarily a conceptual troubleshooting and architecture tool.

Real-world protocols do not always fit perfectly into one isolated OSI layer.

OSI Memory Aids

Layer 7 โ†’ Layer 1

All People Seem To Need Data Processing

Application
Presentation
Session
Transport
Network
Data Link
Physical

Layer 1 โ†’ Layer 7

Please Do Not Throw Sausage Pizza Away

Physical
Data Link
Network
Transport
Session
Presentation
Application

๐Ÿ“ฆ Encapsulation & Protocol Data Units Data gains additional information as it moves down the stack
Application Data โ†“ DATA
Transport โ†“ SEGMENT / DATAGRAM
Network โ†“ PACKET
Data Link โ†“ FRAME
Physical โ†“ BITS / SIGNALS

PDU Memory Aid

DATA Application layers
SEGMENT Transport
PACKET Network
FRAME Data Link
BITS Physical

Data โ†’ Segment โ†’ Packet โ†’ Frame โ†’ Bits

Encapsulation adds context

Each relevant layer adds information needed to perform its function, such as transport ports, network addresses or local-link addressing.

๐ŸŒ TCP/IP Model The practical model underlying modern IP networking
TCP/IP LayerApproximate OSI MappingExamples
ApplicationOSI 5 - 7HTTP, DNS, SMTP, SSH
TransportOSI 4TCP, UDP
InternetOSI 3IPv4, IPv6
Network AccessOSI 1 - 2Ethernet, Wi-Fi, physical media

OSI vs TCP/IP

OSI 7 conceptual layers
TCP/IP 4 practical layers
๐Ÿšš TCP vs UDP Two important transport approaches
TCP

Connection-oriented transport that provides mechanisms for reliable, ordered delivery.

Reliable Ordered Connection-Oriented More Overhead
UDP

Connectionless datagram transport with less transport-layer overhead and no built-in guarantee that data arrives.

Connectionless Low Overhead No Built-In Delivery Guarantee
UDP does not mean unreliable application

An application can implement reliability or recovery itself when its architecture requires it.

๐Ÿ“ฎ IPv4 & IPv6 Logical addressing and packet delivery
IPv4IPv6
Address Size32 bits128 bits
Typical Representation192.0.2.102001:db8::10
BroadcastSupportedNo traditional broadcast
MulticastSupportedSupported and heavily used
AnycastCan be usedSupported
IPv6 is not automatically secure simply because it is newer

IPv6 introduces different addressing, discovery and operational behaviours that must be included in security architecture, filtering and monitoring.

IP Delivery

Unicast ยท Broadcast ยท Multicast ยท Anycast

Unicast

One sender communicates with one destination.

ONE โ†’ ONE

Broadcast

One sender targets all hosts in an applicable broadcast domain.

ONE โ†’ ALL

Multicast

One sender targets members of a particular group.

ONE โ†’ GROUP

Anycast

Multiple systems advertise or represent the same service address and routing delivers traffic to an appropriate instance, commonly the topologically closest.

ONE โ†’ ONE OF MANY

Delivery Memory Aid

UNICAST One
BROADCAST Everybody
MULTICAST Group
ANYCAST One suitable member of many
๐Ÿ” Secure Protocols Protect communication at different parts of the network stack
IPsec

Provides security services for IP communications at the network layer.

Commonly associated with site-to-site and network-layer VPN architectures.

SSH

Provides secure remote shell and related secure communication capabilities.

Frequently used for administrative access.

TLS

Protects communication used by many application protocols.

HTTPS is a common example of HTTP protected using TLS.

Where protection occurs matters

Different technologies protect traffic at different architectural layers and therefore solve different problems.

๐Ÿ›ก๏ธ IPsec Protect IP packets at the network layer
ESP

Encapsulating Security Payload can provide confidentiality and additional security services depending on configuration.

AH

Authentication Header provides integrity and authentication-related protection but does not provide confidentiality.

Transport vs Tunnel Mode

Transport Mode

Protects the payload of the original IP packet while retaining the original outer IP header.

Tunnel Mode

Encapsulates the original IP packet inside a new protected packet.

Common in gateway-to-gateway VPN architecture.

IPsec

TRANSPORT Protect the payload
TUNNEL Protect the original packet inside another packet
๐Ÿช† Implications of Multilayer Protocols Protocols can be nested inside other protocols

Network traffic frequently contains one protocol encapsulated inside another.

Application Data inside TLS
TLS inside TCP
TCP inside IP
IP inside Ethernet

Security Implications

Visibility

Encryption may prevent intermediate devices from inspecting the protected content.

Tunneling

One protocol can carry another through parts of the network.

Policy Bypass

Controls that understand only the outer protocol may not understand what is carried inside it.

Overhead

Additional headers increase packet size and can affect effective transmission capacity.

MTU

Additional encapsulation must be considered when managing maximum packet sizes.

Troubleshooting

Multiple protocol layers make communication paths more complex to analyse.

Multilayer Protocol Risk

OUTSIDE What the control can see
INSIDE What the traffic really contains
๐Ÿ”€ Converged Protocols & Networks Different workloads sharing common infrastructure

Convergence allows different types of traffic and services to use shared network infrastructure.

VoIP iSCSI Storage Traffic Application Traffic InfiniBand over Ethernet Compute Interconnects
Traditional approach

Voice, storage and application traffic may historically have used separate infrastructure.

Converged approach

Multiple traffic types share common switching and transport infrastructure.

Security Considerations

Segmentation

Different workloads may still require logical separation.

Availability

A shared infrastructure failure can affect multiple services.

Quality of Service

Time-sensitive traffic may require prioritisation.

Monitoring

Different traffic types may require different security visibility.

Convergence improves efficiency but can increase concentration risk

Multiple services may fail together if they depend on the same underlying network infrastructure.

๐Ÿ•ธ๏ธ Network Topology How network nodes and paths are arranged
Star

Endpoints connect through a central network device.

Mesh

Multiple paths exist between network nodes.

Point-to-Point

Direct communication path between two locations or devices.

Hub-and-Spoke

Spoke networks communicate through a central hub.

Leaf-Spine

Data-centre topology designed to provide predictable paths between large numbers of connected workloads.

Ring / Bus

Older topology concepts that remain useful when recognising network architecture.

Topology affects both resilience and security

Centralisation can simplify control but may create concentration or availability dependencies.

Multiple paths can improve resilience but increase architecture and monitoring complexity.

โœˆ๏ธ Data, Control & Management Planes One of the most useful network-architecture distinctions
Data Plane

Forwards actual user and application traffic according to existing forwarding decisions.

MOVE THE TRAFFIC

Control Plane

Determines how traffic should be routed or forwarded.

DECIDE THE PATH

Management Plane

Allows administrators and management systems to configure, observe and maintain network infrastructure.

MANAGE THE NETWORK

Router example

A routing protocol learns which path should be used.

Control plane.

The router forwards a customer's packet according to that information.

Data plane.

An administrator connects to configure the router.

Management plane.

The management plane is extremely sensitive

An attacker with administrative control of network devices may be able to change routing, filtering and monitoring behaviour.

Network Planes

DATA FORWARD
CONTROL DECIDE
MANAGEMENT ADMINISTER
โžก๏ธ Cut-Through vs Store-and-Forward How switches handle frames before forwarding
Cut-Through

Begins forwarding after enough of the frame has been received to determine where it should go.

Lower delay, less complete validation before forwarding.

Store-and-Forward

Receives the complete frame before forwarding it.

This allows the device to check the completed frame before sending it onward.

More validation, potentially more latency.

Forwarding

CUT-THROUGH Start forwarding early
STORE-AND-FORWARD Receive first, then forward
Network Performance

Bandwidth ยท Throughput ยท Latency ยท Jitter ยท SNR

Bandwidth

The theoretical or configured capacity of a communication path.

HOW MUCH COULD FLOW?

Throughput

The amount of useful traffic actually being successfully transferred.

HOW MUCH IS FLOWING?

Latency

Delay associated with delivering communication.

HOW LONG?

Jitter

Variation in packet-delivery timing.

HOW CONSISTENT IS THE DELAY?

Signal-to-Noise Ratio

Relationship between the useful signal and unwanted noise.

HOW CLEAR IS THE SIGNAL?

Voice call

A connection may have enough bandwidth but still produce poor voice quality because latency or jitter is excessive.

Performance Memory Aid

BANDWIDTH Capacity
THROUGHPUT Actual delivery
LATENCY Delay
JITTER Variation in delay
SNR Signal quality
โ†”๏ธ North-South vs East-West Traffic Understand where traffic is moving
North-South

Traffic moving into or out of an environment or between major architectural tiers.

Examples include internet users communicating with public applications.

East-West

Traffic moving laterally between internal systems, workloads, servers or services.

Examples include communication between microservices or internal application and database tiers.

๐ŸŒ Internet โ†“ North-South
Public Application โ†” Internal Service
Internal Service โ†” Database
Internal Workloads โ†” East-West
Do not secure only the perimeter

An attacker who compromises one internal workload may attempt to move laterally through east-west traffic paths.

Traffic Flows

NORTH-SOUTH IN / OUT
EAST-WEST ACROSS / LATERAL
Core Security Architecture

Network Segmentation

Segmentation divides a larger environment into smaller security zones.

Communication between those zones can then be controlled according to business and security requirements.

User Network โ†’ Controlled Boundary
Application Network โ†’ Controlled Boundary
Database Network โ†’ Highly Restricted
Management Network โ†’ Administrative Access Only
Segmentation reduces blast radius

Compromise of one segment should not automatically provide unrestricted access to every other part of the organisation.

๐Ÿ”Œ Physical Segmentation Separate networks using physical infrastructure or paths
Separate Infrastructure

Different networks can use distinct switches, cabling and other hardware.

Air Gap

A system or network is intentionally isolated from direct network connectivity with other environments.

Out-of-Band Management

Administrative communication uses a path separate from ordinary production traffic.

In-Band Management

Management traffic shares the same general network infrastructure as production communication.

Air-gapped โ‰  impossible to compromise

Physical isolation reduces direct network attack paths, but removable media, maintenance devices, personnel and supply-chain paths can still introduce risk.

Management Networks

IN-BAND Management shares production path
OUT-OF-BAND Separate management path
๐Ÿงฉ Logical Segmentation Separate traffic while sharing physical infrastructure
VLAN

Virtual Local Area Network logically separates Layer 2 network domains.

VRF

Virtual Routing and Forwarding allows separate routing instances to exist on shared routing infrastructure.

VPN

Creates a logical communication path across another network and commonly uses cryptography to protect the traffic.

Virtual Domain

Allows infrastructure to support logically separate security or administrative contexts.

Logical separation still depends on configuration

A misconfigured routing, firewall or virtualisation policy can undermine logical segmentation even though the architecture appears separated on paper.

Physical vs Logical

PHYSICAL Separate infrastructure
LOGICAL Shared infrastructure ยท Separate configuration
๐Ÿงฌ Microsegmentation Apply fine-grained controls between individual workloads or services

Traditional segmentation may separate broad groups such as users, applications and databases.

Microsegmentation applies much more granular control.

App A โ†’ Only required service
App B โ†’ Different permitted flows
Database โ†’ Only authorised workloads

Possible Technologies

Distributed Firewalls Host / Workload Policies Network Overlays Virtual Routers IDS / IPS Identity-Aware Controls
Traditional segmentation

100 application servers exist inside one application VLAN.

They may all be able to communicate with each other unless additional controls exist.

Microsegmentation

Application Server A is allowed to communicate only with:

Identity Service + Payment API + required database service.

Unnecessary lateral communication is blocked.

Segmentation Scale

SEGMENTATION Separate zones
MICROSEGMENTATION Separate workloads
๐Ÿ›ก๏ธ Zero Trust Network Architecture Network location alone should not create implicit trust

Traditional network designs often placed significant trust in systems simply because they were located inside the organisational network.

Zero trust changes the emphasis toward protecting individual resources and making access decisions based on stronger contextual information.

User + Identity
Device + Security State
Requested Resource + Policy
Context โ†’ Access Decision
"Inside the network" is not sufficient proof of trust

A compromised internal system should not automatically receive broad access simply because of its network location.

Zero trust โ‰  trust nobody and block everything

Access is still granted.

The difference is that access decisions should be explicitly evaluated rather than assumed from location alone.

Zero Trust

NO IMPLICIT TRUST Because you are "inside"
VERIFY Identity and context
LIMIT Access to what is required
๐ŸŒ Edge Networks Where the organisation connects to other networks
Ingress

Traffic entering an environment.

IN

Egress

Traffic leaving an environment.

OUT

Peering

Networks establish connectivity relationships allowing traffic to move between their routing domains.

Edge Security Questions

What traffic may enter? What traffic may leave? Which routes are trusted? Which partners connect? Can spoofed traffic be filtered? Can abnormal traffic volumes be handled?
Egress matters too

Network architecture should not focus only on stopping malicious traffic entering.

Controlling outbound communication can help reduce data exfiltration, command-and-control communication and accidental exposure.

๐Ÿ“ถ Wireless Networks Communication can extend beyond the physical walls of the organisation

Wireless technologies transmit through radio or other non-wired media, changing the physical attack surface.

Wi-Fi

Common local wireless networking technology.

Bluetooth

Short-range wireless connectivity between devices.

Zigbee

Low-power wireless technology often associated with IoT and automation environments.

Satellite

Provides communication across large geographic distances using satellite infrastructure.

Wireless Architecture Risks

Eavesdropping Rogue Access Points Unauthorised Association Interference Jamming Weak Authentication Poor Encryption Unexpected Signal Range
Physical boundary problem

A wired network normally requires physical connection to network infrastructure.

A wireless signal may extend into:

Car Parks Neighbouring Offices Public Areas Outside the Building
The building wall is not necessarily the wireless boundary

Wireless architecture must consider authentication, encryption, segmentation and actual radio coverage.

๐Ÿ“ฑ Cellular & Mobile Networks 4G and 5G extend enterprise communication beyond traditional LANs

Mobile networks provide wide-area connectivity through carrier infrastructure.

Security Considerations

Device Identity

Devices and subscribers require appropriate authentication.

Carrier Dependency

The organisation depends on infrastructure outside its direct control.

Roaming

Communication may cross additional network and trust boundaries.

Network Segmentation

Different services and network functions may require separation.

Management

Control and management functions require strong protection.

Availability

Coverage, congestion and provider outages affect connectivity.

๐ŸŒŽ Content Distribution Networks - CDN Distribute content closer to users
Origin Application โ†’ CDN
CDN Edge Location โ†’ Users

Benefits

Lower Latency Reduced Origin Load Geographic Distribution Scalability Resilience

Security Considerations

Origin Protection TLS Configuration Cache Security DNS Security Access Control DDoS Resilience
Architecture mistake

A public application uses a CDN for protection.

However, the origin server remains directly reachable from the internet.

An attacker may bypass the CDN and target the origin directly.

CDN

CACHE Closer to user
DISTRIBUTE Across locations
PROTECT The origin too
๐Ÿง  Software-Defined Networking - SDN Move more network control into programmable software

Software-defined networking separates network-control logic from the underlying devices that forward traffic.

Applications / Policy โ†’ SDN Controller
SDN Controller โ†’ Network Devices
Network Devices โ†’ Forward Traffic

Advantages

Automation Central Policy Programmability Rapid Provisioning Consistent Configuration

Security Considerations

Controller Security

The controller can become a highly valuable concentration point.

API Security

Programmatic management interfaces require strong authentication and authorisation.

Availability

Control infrastructure must be resilient.

Change Control

Automation can deploy both correct and incorrect policy very quickly.

Centralised control creates both power and risk

The ability to change the network globally makes the SDN controller especially important to protect.

๐Ÿ—บ๏ธ Software-Defined WAN - SD-WAN Software-driven control of wide-area connectivity

SD-WAN applies software-defined principles to wide-area network connectivity.

Potential Capabilities

Central Policy Dynamic Path Selection Multiple WAN Links Application-Aware Routing Central Management
The control system becomes critical

Central orchestration and management interfaces require appropriate identity, access, resilience and monitoring controls.

๐Ÿ“ฆ Network Functions Virtualization - NFV Run network functions as software rather than dedicated appliances

Network functions that historically required dedicated hardware may be implemented as virtualised software functions.

Virtual Firewall Virtual Router Virtual Load Balancer Virtual IDS / IPS
Virtual does not mean security responsibility disappears

The network function now depends on the security of its virtualisation, orchestration, management and underlying compute infrastructure.

SDN vs NFV

SDN Programmable CONTROL
NFV Virtualise network FUNCTIONS
โ˜๏ธ Virtual Private Cloud - VPC Logical network isolation inside cloud infrastructure

A Virtual Private Cloud provides a logically isolated network environment within a cloud platform.

Typical Architecture Concepts

Address Ranges Subnets Routing Security Policies Private Connectivity Gateways Peering
Public Subnet โ†’ Internet-facing components
Application Subnet โ†’ Internal workloads
Database Subnet โ†’ Restricted data services
VPC โ‰  secure by default

Logical isolation provides architectural capability, but routing, identities, security policies and external connectivity still need secure configuration.

๐Ÿ‘๏ธ Network Observability You cannot effectively protect what you cannot understand

Network observability provides information about how infrastructure and traffic are behaving.

Logs

Record events from network infrastructure.

Flow Data

Summarises communication relationships and traffic flows.

Packet Visibility

Detailed packet information may support troubleshooting and investigation where appropriate.

Telemetry

Provides measurements about performance and infrastructure state.

Topology

Shows how systems and network paths relate to each other.

Baselines

Normal behaviour provides context for detecting significant change.

Visibility should include east-west traffic

Monitoring only internet-facing boundaries can leave internal lateral communication poorly understood.

๐Ÿšฆ Traffic Flow & Shaping Manage how network capacity is consumed

Network architecture may prioritise, limit or shape traffic according to business requirements.

Example

A converged network carries:

Voice Video Backups Web Traffic

Large backup transfers should not necessarily be allowed to consume all available bandwidth and destroy the quality of latency-sensitive voice calls.

Traffic Management Supports

Quality of Service Prioritisation Rate Limiting Capacity Protection Fair Usage
๐Ÿ“ˆ Capacity Management Availability depends on having sufficient resources

Network capacity should support expected normal demand as well as appropriate peaks, growth and resilience requirements.

Measure โ†’ Current usage
Trend โ†’ Growth
Forecast โ†’ Future requirement
Provide โ†’ Adequate capacity
Capacity is a security consideration

Exhausted network resources can produce an availability failure even without a traditional security exploit.

๐Ÿšจ Fault Detection & Handling Secure networks should fail predictably and recoverably
Detect โ†’ Something failed
Identify โ†’ Which component?
Contain โ†’ Limit impact
Failover โ†’ Use alternate path where appropriate
Recover โ†’ Restore normal operation
Redundancy needs detection

Having a backup path helps only if the architecture can identify the failure and successfully use the alternative path when required.

Practical Scenario

Designing a Secure Banking Network

Consider a customer-facing banking platform.

๐ŸŒ Internet โ†’ Edge / CDN
Edge โ†’ Public Application Tier
Public Tier โ†’ Application Services
Application Services โ†’ Database Services
Administrators โ†’ Separate Management Path
Cloud Workloads โ†’ VPC / Segmented Cloud Network

Architecture Decisions

Internet Traffic

Only required public services are reachable.

Application Tier

Cannot freely communicate with every internal resource.

Database

Accepts only required flows from authorised application services.

Administration

Management access is separated from ordinary customer traffic.

East-West Traffic

Internal service-to-service communication is controlled and monitored.

Observability

Important traffic and network events are available for monitoring.

The goal is not "put everything behind a firewall."

The goal is to understand and control every important trust boundary and communication path.

Security Scenario

One Server Is Compromised

Assume an attacker compromises one web server.

Flat Network

The web server can communicate freely with:

Other Servers Databases Administration Systems File Servers

Large blast radius.

Segmented Network

The web server can communicate only with:

Required Application API Required DNS Required Monitoring

Smaller blast radius.

Segmentation

PREVENT Unnecessary communication
LIMIT Lateral movement
REDUCE Blast radius
๐ŸŽ“ CISSP Scenarios Recognise the network architecture principle
Scenario 1

A security engineer is analysing IP routing between networks.

Which OSI layer is most relevant?

Layer 3 - Network.

Scenario 2

A switch processes Ethernet frames using MAC addresses.

Which OSI layer?

Layer 2 - Data Link.

Scenario 3

An application uses TCP ports for end-to-end communication.

Which OSI layer?

Layer 4 - Transport.

Scenario 4

One packet is sent directly to one destination host.

Delivery type?

Unicast.

Scenario 5

Traffic is sent to all members of a particular subscribed group.

Delivery type?

Multicast.

Scenario 6

Several geographically distributed servers represent the same service address and routing directs users to an appropriate instance.

Delivery concept?

Anycast.

Scenario 7

A site-to-site VPN needs to protect IP traffic between two network gateways.

Which protocol family is particularly relevant?

IPsec.

Scenario 8

An administrator requires an encrypted command-line session to a network device.

Which protocol?

SSH.

Scenario 9

Web application traffic requires cryptographic protection between a browser and server.

Which protocol is most relevant?

TLS.

Scenario 10

An organisation places users and critical database servers on different VLANs.

Which concept?

Logical segmentation.

Scenario 11

Two networks use entirely separate switches and cabling.

Which concept?

Physical segmentation.

Scenario 12

Security policy restricts communication between individual application workloads even though they exist in the same broad cloud environment.

Which architecture?

Microsegmentation.

Scenario 13

A user is located on the internal corporate LAN but must still authenticate and satisfy access policy before reaching a protected resource.

Which principle?

Zero trust.

Scenario 14

Traffic travels between two internal microservices.

Which traffic-flow term?

East-west.

Scenario 15

Customer traffic enters the organisation from the internet.

Which traffic-flow term?

North-south.

Scenario 16

A routing protocol determines the best network path.

Which network plane?

Control plane.

Scenario 17

A router sends a normal application packet according to its forwarding table.

Which plane?

Data plane.

Scenario 18

An engineer changes the configuration of a network switch.

Which plane?

Management plane.

Scenario 19

Network administration uses infrastructure that is physically or logically separated from production traffic.

Which concept?

Out-of-band management.

Scenario 20

Two servers are placed on an air-gapped network.

Management claims this makes compromise impossible.

What is wrong with the statement?

Air gaps remove direct network connectivity but other attack paths, such as removable media and human interaction, can still exist.

Scenario 21

Voice traffic becomes unusable because packets arrive with highly inconsistent delays.

Which metric?

Jitter.

Scenario 22

A 10 Gbps network connection delivers only 6 Gbps of actual useful traffic.

10 Gbps represents what?

Bandwidth / capacity.

6 Gbps represents what?

Throughput.

Scenario 23

The organisation virtualises firewalls and routers instead of using a separate physical appliance for every function.

Which concept?

Network Functions Virtualization - NFV.

Scenario 24

Network behaviour is centrally programmed through a controller and APIs.

Which architecture?

Software-Defined Networking - SDN.

Scenario 25

A public web service uses a CDN but the origin server remains directly reachable from anywhere on the internet.

Primary architectural concern?

Attackers may bypass the CDN and directly target the origin.

Scenario 26

A cloud environment separates internet-facing applications, application services and databases into different logical network areas.

Which concept?

VPC segmentation.

Scenario 27

A company monitors traffic entering from the internet but has almost no visibility into internal server-to-server communication.

Which visibility gap?

East-west traffic visibility.

Scenario 28

A switch begins transmitting a frame before receiving the complete frame.

Which forwarding approach?

Cut-through.

Scenario 29

A switch receives the entire frame and validates it before forwarding.

Which approach?

Store-and-forward.

Scenario 30

Several network security controls are configured correctly, but demand grows until all available network capacity is consumed.

Which management activity was insufficient?

Capacity management.

CISSP Exam Perspective

Recognise the Clue Words

MAC / Ethernet

Local frames.

Layer 2

IP / Router

Logical addressing and routing.

Layer 3

TCP / UDP / Ports

End-to-end transport.

Layer 4

Data โ†’ Segment โ†’ Packet โ†’ Frame

Move down the stack.

Encapsulation

One โ†’ One

Individual destination.

Unicast

One โ†’ Group

Group communication.

Multicast

One of Many

Same service in multiple places.

Anycast

Network-Layer VPN

Protect IP traffic.

IPsec

Secure Command Line

Administrative communication.

SSH

Secure Web Traffic

Application communication protection.

TLS

Traffic Inside Traffic

Nested protocols.

Encapsulation / Multilayer Protocol

Voice + Storage + Data

Shared infrastructure.

Convergence

Move Traffic

Packet forwarding.

Data Plane

Choose Route

Network decisions.

Control Plane

Configure Network

Administration.

Management Plane

Capacity

Potential amount.

Bandwidth

Actual Transfer

Real achieved rate.

Throughput

Delay

Time taken.

Latency

Variable Delay

Especially important for voice/video.

Jitter

Into / Out of Environment

Perimeter-style flow.

North-South

Server-to-Server

Lateral traffic.

East-West

Separate Hardware

Distinct infrastructure.

Physical Segmentation

VLAN / VRF

Shared hardware, logical separation.

Logical Segmentation

Workload-Level Controls

Very granular isolation.

Microsegmentation

No Trust Based on Location

Explicit policy decisions.

Zero Trust

Traffic Entering

Network edge.

Ingress

Traffic Leaving

Network edge.

Egress

Distributed Content

Closer to users.

CDN

Central Network Controller

Programmable networking.

SDN

Virtual Firewall / Router

Software network functions.

NFV

Isolated Cloud Network

Subnets and cloud routing.

VPC

Logs / Flows / Telemetry

Understand network behaviour.

Observability
โš ๏ธ Common CISSP Mistakes Network questions frequently test architecture rather than commands
OSI โ‰  TCP/IP

OSI uses seven conceptual layers while the commonly used TCP/IP model groups functionality into fewer layers.

Switch โ‰  Router

Traditional switching is primarily associated with Layer 2.

Routing is primarily associated with Layer 3.

Bandwidth โ‰  Throughput

Bandwidth represents capacity.

Throughput represents what is actually being transferred.

Latency โ‰  Jitter

Latency is delay.

Jitter is variation in delay.

IPv6 โ‰  IPv4 with Bigger Addresses Only

IPv6 changes several aspects of addressing and network operation and should receive its own security consideration.

Encryption โ‰  Complete Network Security

Encryption may protect data while segmentation, authentication, routing and monitoring remain weak.

Internal โ‰  Trusted

Network location alone should not justify unrestricted access.

VLAN โ‰  Microsegmentation

A VLAN may contain many workloads that can communicate freely unless additional controls restrict them.

Air Gap โ‰  Impossible to Attack

Other physical, removable-media and human paths may remain.

Two Networks โ‰  Independent Networks

They may share the same physical path, provider, device or management infrastructure.

North-South Monitoring โ‰  Complete Visibility

Attackers can move laterally using east-west communication.

SDN โ‰  NFV

SDN focuses on programmable network control.

NFV virtualises network functions.

VPC โ‰  Secure by Default

Cloud network security still depends on routing, policy, identity and configuration.

CDN โ‰  Origin Automatically Protected

The origin must also be architected so attackers cannot simply bypass the CDN.

Monitoring โ‰  Response

Visibility is useful only when abnormal behaviour can be analysed and acted upon.

Quick Reference

If you see...Think...
MAC address / Ethernet frameOSI Layer 2
IP address / routingOSI Layer 3
TCP / UDP / portOSI Layer 4
Data โ†’ Segment โ†’ Packet โ†’ Frame โ†’ BitsEncapsulation
One destinationUnicast
Everyone in broadcast domainBroadcast
Defined groupMulticast
One instance from severalAnycast
Protect IP packetsIPsec
Secure administrative shellSSH
Secure application transportTLS
Forward normal trafficData Plane
Determine routesControl Plane
Configure devicesManagement Plane
Potential network capacityBandwidth
Actual transfer rateThroughput
DelayLatency
Variable delayJitter
Traffic entering or leaving environmentNorth-South
Internal lateral trafficEast-West
Separate switches / cablingPhysical Segmentation
VLAN / VRFLogical Segmentation
Fine-grained workload isolationMicrosegmentation
No implicit trust from network locationZero Trust
Traffic enteringIngress
Traffic leavingEgress
Content cached near usersCDN
Programmable controllerSDN
Virtual firewall / routerNFV
Software-managed WANSD-WAN
Logically isolated cloud networkVPC
Flows, logs and telemetryNetwork Observability

Domain 4.1 Master Memory Aid

LAYERS How does communication work?
ADDRESS Where is traffic going?
PROTOCOL How is it transported and protected?
FLOW North-south or east-west?
SEGMENT What should be separated?
CONTROL What communication is permitted?
OBSERVE Can we see what is happening?
RESILIENT What happens when a path fails?

Layers ยท Address ยท Protocol ยท Flow ยท Segment ยท Control ยท Observe ยท Resilient

The Network Architect's Questions

WHO? Which users, devices and services communicate?
WHERE? Which network or security zone are they in?
WHY? Is the communication actually required?
HOW? Which protocol and path are used?
PROTECTED? Does the communication need confidentiality or integrity?
CONTROLLED? What prevents unnecessary communication?
VISIBLE? Can security teams observe the flow?
FAIL? What happens if the path or component disappears?

Key Takeaways

Secure network architecture controls how systems communicate and where network trust boundaries exist.

The OSI model provides seven conceptual layers, while the TCP/IP model combines network communication into fewer practical layers.

A useful encapsulation memory aid is: Data โ†’ Segment โ†’ Packet โ†’ Frame โ†’ Bits.

Layer 2 is strongly associated with Ethernet frames, MAC addresses and switching, while Layer 3 is associated with IP addressing and routing.

Layer 4 provides transport capabilities through protocols such as TCP and UDP.

IPv4 uses 32-bit addresses while IPv6 uses 128-bit addresses.

Unicast means one-to-one, multicast means one-to-group, broadcast means one-to-all within the applicable broadcast domain, and anycast directs traffic to one suitable instance among multiple instances.

Secure protocols operate at different architectural layers. IPsec protects IP communication, SSH provides secure remote communication and TLS protects many application communication protocols.

Multilayer protocols create security considerations because traffic can be encapsulated and controls may see only part of the complete protocol stack.

Converged networks improve infrastructure efficiency but may concentrate risk when voice, storage and application traffic depend on the same underlying network.

The data plane forwards traffic, the control plane determines paths and the management plane administers the network.

Bandwidth represents capacity, while throughput represents actual successful data transfer.

Latency is communication delay, while jitter is variation in delay.

North-south traffic generally enters or leaves an environment, while east-west traffic moves laterally between internal workloads and systems.

Monitoring only north-south traffic can leave attacker lateral movement through east-west paths poorly visible.

Physical segmentation uses separate infrastructure or communication paths.

Logical segmentation uses technologies such as VLANs, VRFs, VPNs and virtual security domains while sharing underlying infrastructure.

Microsegmentation provides much more granular control between individual workloads and services.

Segmentation reduces unnecessary connectivity, limits lateral movement and reduces the potential blast radius of compromise.

Zero trust removes the assumption that network location alone should create implicit trust.

Edge architecture should consider both ingress and egress communication, including external routing and peering relationships.

Wireless communication changes the physical security boundary because radio signals can extend beyond organisational walls.

CDNs distribute content closer to users but the underlying origin should also be protected against direct bypass.

SDN provides programmable network control, while NFV implements network functions as virtualised software.

SD-WAN applies software-defined control concepts to wide-area network connectivity.

A VPC provides logical cloud network isolation but still requires secure routing, access policies and configuration.

Network observability uses information such as logs, flows, packets, topology and telemetry to understand behaviour.

Capacity and fault management are security considerations because resource exhaustion or infrastructure failure can directly affect availability.

The key CISSP principle is not simply to connect systems securely. It is to permit only necessary communication, protect important flows, minimise implicit trust, reduce blast radius and maintain visibility across the architecture.

๐Ÿ“š Sources & Further Reading Network architecture and protocol references