CISSP · Domain 4
Communication and Network Security
About 13% of the exam
OSI model, top to bottom
- 7 Application
- HTTP, DNS, SMTP, FTP, user-facing protocols
- 6 Presentation
- encoding, compression, formats like JPEG, ASCII
- 5 Session
- dialog setup and teardown, RPC, NetBIOS
- 4 Transport
- TCP, UDP, ports, segments, flow control
- 3 Network
- IP, ICMP, routers, packets, logical addressing
- 2 Data Link
- Ethernet, MAC, switches, frames, ARP
- 1 Physical
- cables, hubs, repeaters, bits on the wire
Data Link splits into LLC (flow and error control) above MAC (hardware addressing and medium access); TCP/IP collapses the top three into one Application layer
TCP/IP and addressing
- IPv4: 32 bits, dotted decimal
- IPv6: 128 bits, eight hex groups
- IPsec is optional in both versions
- NDP replaces ARP, spoofable like ARP
- SLAAC from MAC leaks hardware identity
- RFC 1918 private ranges behind NAT
- TCP: handshake, ordered, acknowledged, retransmits
- UDP: connectionless, fast, best effort
- ICMP: errors and diagnostics, ping, traceroute
Ports to recognize
- 20, 21
- FTP data and control
- 22
- SSH, SFTP, SCP
- 23
- Telnet, cleartext
- 25, 587
- SMTP relay, submission
- 49
- TACACS+ over TCP
- 53
- DNS name resolution
- 80, 443
- HTTP, HTTPS
- 88
- Kerberos ticket exchange
- 161, 162
- SNMP, SNMP traps
- 389, 636
- LDAP, LDAPS
- 445
- SMB file sharing
- 500, 4500
- IKE, NAT traversal
- 1812, 1813
- RADIUS authentication, accounting
- 3389
- RDP remote desktop
Securing protocols
- TLS 1.3
- forward secrecy, one round trip
- SSH
- replaces Telnet, rlogin, FTP
- S/MIME, PGP
- signed and encrypted email
- SPF, DKIM, DMARC
- authorized senders, signatures, policy
- DNSSEC
- signed records, integrity not confidentiality
- DoH, DoT
- encrypted DNS queries
- SNMPv3
- only version with encryption
- 802.1X
- port-based network access control
- QUIC
- UDP transport with TLS 1.3 built in
- SRTP
- protects VoIP media streams
Network devices and segmentation
- Hub
- layer 1, repeats to every port
- Switch
- layer 2, forwards by MAC
- Router
- layer 3, forwards by IP
- Proxy
- terminates and relays sessions
- Load balancer
- distributes, sticky sessions persist
- VLAN
- logical segment on one switch
- Private VLAN
- isolated ports, same VLAN
- NAC
- check posture before admitting
- Screened subnet
- public services between two firewalls
- Air gap
- no connection at all
Firewall generations
- Packet filter: layer 3 and 4, stateless
- Stateful: tracks connection table
- Application proxy: layer 7 content
- Next generation: app awareness plus IPS
- Rules processed top down, first match wins
- Implicit deny at the bottom
- WAF guards web apps specifically
- IDS alerts, IPS sits inline and blocks
- Signature, anomaly, heuristic detection
Wireless security
- WEP
- RC4, broken, never use
- WPA
- TKIP, deprecated
- WPA2
- AES-CCMP, still acceptable
- WPA3
- SAE handshake, forward secrecy
- Personal vs Enterprise
- shared passphrase vs 802.1X
- EAP-TLS
- certificates both sides, strongest
- PEAP
- server cert, tunneled inner auth
- Hidden SSID
- obscurity, not a control
- Evil twin
- rogue AP with familiar name
- Bluesnarfing
- steal data over Bluetooth
- Site survey
- place APs, limit leakage
Network attacks by layer
Layer 2
- ARP poisoning: gratuitous replies, fake gateway
- MAC flooding turns switch into hub
- VLAN hopping via double tagging
- Rogue DHCP hands out bad DNS
- Fix: dynamic ARP inspection, port security, DHCP snooping
Layer 3 and 4
- IP spoofing, ingress and egress filtering
- SYN flood exhausts the connection table
- Smurf and fraggle: ICMP, UDP amplification
- BGP hijack: more specific prefix wins
- Fix: RPKI, SYN cookies, rate limits
Upper layers
- DNS cache poisoning redirects users
- DNS amplification DDoS
- On-path (man in the middle) interception
- Session hijacking steals cookies
- Fix: DNSSEC, TLS, mutual authentication
BGP trusts what peers announce; ARP trusts what the LAN says; DNS trusts what the resolver cached. Each attack abuses trust by default
VPN and remote access
- IPsec site to site
- gateway to gateway tunnel
- TLS VPN
- clientless, browser only
- IKE phase 1
- secure channel, main mode 6 messages
- Aggressive mode
- 3 messages, identity exposed
- IKE phase 2
- negotiates the IPsec SAs
- IKEv2 MOBIKE
- survives address changes
- Split tunnel
- internet bypasses corporate inspection
- L2TP over IPsec
- L2TP tunnels, IPsec protects
- PPTP
- obsolete, broken authentication
Zero trust and modern architecture
- Never trust, always verify, every request
- Location no longer implies trust
- Microsegmentation shrinks blast radius
- SDP: single packet authorization, invisible services
- SDN: controller decides, switches forward
- SD-WAN routes over any transport
- SASE: network and security from the cloud edge
- CASB polices SaaS use
- CDN absorbs DDoS, fronts a WAF
Converged and specialized networks
- VoIP
- SIP signals, RTP carries, SRTP protects
- Vishing, SPIT
- voice phishing, spam over IP
- FCoE, iSCSI
- storage traffic on Ethernet, IP
- ICS, SCADA
- Modbus, isolate, availability first
- IoT
- segment, no agents, weak updates
- Cellular 5G
- carrier network, still encrypt end to end
- Satellite
- latency, wide capture footprint
- Li-Fi
- light-based, contained by walls
- Zigbee
- low-power mesh, IoT
Media and topologies
- Twisted pair
- cheap, crosstalk, Cat 6 and up
- Coaxial
- shielded, older bus networks
- Fiber
- immune to EMI, hardest to tap
- CSMA/CD
- Ethernet detects collisions
- CSMA/CA
- wireless avoids collisions
- Star
- central switch, one link fails
- Mesh
- many paths, most resilient
- Ring, bus
- legacy, one break hurts all
- Baseband
- one signal, Ethernet
- Broadband
- many channels, cable
Know the order: encapsulation
- Data
- Segment (TCP) or datagram (UDP)
- Packet
- Frame
- Bits
- TCP handshake: SYN, SYN-ACK, ACK
- Teardown: FIN, ACK, FIN, ACK
- RST aborts a connection abruptly
- Sending adds headers going down
- Receiving strips headers going up
Rapid recall: IPsec
- AH
- integrity and origin, no encryption
- ESP
- confidentiality, integrity, optional auth
- Transport mode
- protects payload only
- Tunnel mode
- wraps whole original packet
- Security association
- one direction, one protocol
- SPI
- identifies the SA in each packet
- ISAKMP
- framework IKE uses to negotiate
- NAT breaks AH
- AH hashes the changed header
Reference strip: standards and protocols
IEEE 802 family
- 802.3 wired Ethernet
- 802.11 Wi-Fi, 802.11i security
- 802.1X port authentication
- 802.1Q VLAN tagging
- 802.1AE MACsec link encryption
- 802.15 Bluetooth and Zigbee
AAA protocols
- RADIUS: UDP, encrypts password only
- TACACS+: TCP 49, encrypts whole body
- TACACS+ separates the three A functions
- Diameter: RADIUS successor for telecom
- Kerberos: tickets, symmetric, port 88
Email and DNS
- SPF lists permitted sending hosts
- DKIM signs outgoing messages
- DMARC sets policy over SPF and DKIM
- DNSSEC signs zones against poisoning
- Sinkhole DNS blocks known bad domains
Frameworks
- NIST SP 800-207 zero trust architecture
- NIST SP 800-41 firewall guidance
- NIST SP 800-77 IPsec VPNs
- NIST SP 800-82 ICS security
- RPKI for BGP origin validation
Names to place
- Bastion host: hardened, exposed
- Honeypot: decoy to observe attackers
- Jump box: single admin entry point
- Extranet: partners; intranet: staff
- Content filter, DLP at egress
Quick exam traps
- Trap: RADIUS encrypts the entire packet
- Trap: IPv6 forces IPsec on every packet
- Trap: Hiding the SSID is a security control
- Trap: Stateful firewalls inspect application payloads
- Trap: The most specific firewall rule wins regardless of position
- Trap: Switches make packet sniffing impossible
- Trap: IPsec AH provides encryption
- Trap: WPA2 with TKIP is as strong as CCMP
cybercertprep.com · original revision sheet written from the public body of knowledge