certslothcertsloth
CCSP/Topic 01

ISC2 / Professional

Secure Architecture and Network Defences

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Reduce exposure; separate trust; inspect the right layer.

Must remember

Security responsibility changes across IaaS, PaaS and SaaS. Customers retain responsibilities for their data, identities and configuration even when infrastructure is managed. Virtual machines share a hypervisor; containers normally share the host kernel. Isolation, patching and image provenance remain important.

Segment systems by sensitivity and function: user networks, guests, servers, management, IoT and operational technology. A screened subnet/DMZ hosts externally reachable services while restricting movement inward. Air gaps and logical isolation differ; removable media and maintenance paths can still introduce risk. Industrial systems prioritize safety and availability, so patching may require controlled maintenance and compensating safeguards.

Control Deciding role
Stateful firewall / ACL Permit or deny network flows at the relevant enforcement point.
WAF Inspect web application requests; supplement secure application code.
IDS / IPS Detect / potentially block suspicious traffic.
Proxy / secure web gateway Mediate outbound web access and policy.
NAC Assess/authorize device network admission.
VPN Protect a tunnel; endpoint compromise remains possible.
DLP Discover and restrict sensitive-data movement.
EDR / XDR Endpoint detection/response / correlation across broader sources.

Choose fail-open versus fail-closed behavior according to safety and availability requirements. A load balancer improves distribution/availability; it is not a substitute for authentication. Secure management interfaces separately from application traffic, prefer encrypted protocols and restrict administrative access.

Wireless protection includes WPA3 or appropriate enterprise authentication, secure onboarding, guest isolation and removal of legacy protocols. An evil twin imitates a legitimate network; validate the authentication server certificate in enterprise Wi-Fi rather than accepting any certificate prompt.

IaC makes configuration repeatable but also makes a bad template repeatable. Review plans, scan configurations, protect state and control deployment credentials.

Choose under exam pressure

Requirement Choice and reason
Block common web-request attacks WAF plus application-layer fixes.
Untrusted guest devices Separate network and restricted routing/access.
Legacy industrial controller cannot be patched now Approved segmentation, monitoring and maintenance planning.

Traps

  • A VPN does not make the endpoint trustworthy.
  • Containers are not equivalent to separate hardware trust boundaries.

Active recall

1. IDS versus IPS?

IDS detects/alerts; an IPS can enforce blocking in the traffic path.

2. Why isolate management interfaces?

Compromise of administration can bypass normal application protections.

3. Why not immediately patch every industrial system?

Safety, compatibility and availability require controlled testing and maintenance.

4. What can a WAF not replace?

Correct authentication, authorization and secure application design.

5. What is shared responsibility in SaaS?

The provider runs more of the stack, but customers still manage appropriate identities, data and tenant configuration.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.