Skip to content
ISC2 CISSP · CISSP

CISSP Domain 4: Communication and Network Security

Domain 4.0: Communication and Network Security · 13% of the exam

Networks designed, built and operated securely: all 3 objectives (4.1–4.3), from the reference models and secure protocols through segmentation at three grades, north-south against east-west traffic, wireless and cellular, software-defined networking and virtual private clouds, then securing the components and the communication channels people actually use.

3 modules · 19 topics 86-page PDF 60 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$129one-time · all 8 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

13% of your exam score

Domain 4.0 is worth 13% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CISSP objectives 4.1–4.3: 19 in-depth topics with worked scenarios and exam tips, in a 86-page guide you'll actually finish.

60 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cert that changes what you're paid

CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.

Serving, transitioning, or a military spouse?

CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 4.1, Secure network architecture, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 4.1

Apply secure design principles in network architectures

Reference models, addressing, secure protocols, segmentation at three grades, traffic direction, wireless and cellular, SDN and virtual private clouds.

Sam Oduya's network diagram for Aurora Logistics had 11 sites, 3 cloud regions, 4 port terminals with operational technology, 40,000 handheld devices on cellular, a partner extranet reaching 900 customs brokers, and one flat layer-2 domain spanning two data centres that had been created “temporarily” in 2019 for a migration. Every principle in this objective was visible somewhere on that page, including in its failures.

The reference models

#OSI layerUnitDevices and protocolsCharacteristic attacks
7ApplicationDataHTTP, DNS, SMTP, FTP, SNMPInjection, XSS, application DoS
6PresentationDataEncoding, encryption, compression, TLS conceptuallyMalformed encoding, compression side channels
5SessionDataDialogue control, RPC, NetBIOSSession hijacking
4TransportSegmentTCP, UDP, portsSYN flood, port scanning, session prediction
3NetworkPacketIP, ICMP, routers, IPSecIP spoofing, smurf, routing attacks, fragmentation
2Data linkFrameMAC, switches, ARP, VLANs, 802.1XARP poisoning, MAC flooding, VLAN hopping
1PhysicalBitCabling, hubs, repeaters, radioWiretapping, jamming, cable cutting

The TCP/IP model collapses these into four: link (OSI 1–2), internet (3), transport (4), and application (5–7). Encapsulation adds a header at each layer descending the stack and removes it ascending — which is why a firewall inspecting at layer 4 cannot see what a layer-7 firewall sees.

Exam focus · Layer-matching questions

A large share of Domain 4 questions give you a protocol, a device or an attack and ask for the layer. Learn the table above rather than a mnemonic alone. Two frequent traps: ARP is layer 2 despite resolving layer-3 addresses, and a switch is layer 2 unless the question says multilayer or layer-3 switch.

IP and addressing

ConceptDetail
IPv4 vs IPv632-bit versus 128-bit addressing. IPv6 has no broadcast, uses multicast and anycast instead, and includes IPSec support in its design. The security risk in practice is unmanaged IPv6 running alongside IPv4 with no equivalent filtering.
Unicast / broadcast / multicast / anycastOne-to-one; one-to-all on the segment; one-to-many subscribers; one-to-nearest of many, which is how CDNs and DNS root servers work.
Private ranges and NATRFC 1918 ranges behind network address translation. NAT provides obscurity and address conservation, not security — treating it as a control is a classic error.
DNSFrequently abused for exfiltration and command and control because it is rarely blocked. DNSSEC signs records for authenticity and integrity; it does not encrypt. DoH and DoT encrypt the query and complicate inspection.
The guide continues for 86 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.

From module 4.1 · Secure network architecture

  1. 1. At which OSI layer does ARP poisoning occur?

From module 4.2 · Securing network components

  1. 1. What distinguishes a stateful firewall from a packet-filtering firewall?

From module 4.3 · Secure communication channels

  1. 1. What is the essential difference between a traditional VPN and zero trust network access?

57 more questions like these are waiting inside.

What's inside

  • 19 in-depth topics across 3 modules, mapped to objectives 4.1–4.3
  • 60 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • Every OSI layer mapped to its devices, protocols and attacks
  • Third-party connectivity: the most common way in, handled properly
  • Complete CISSP acronym & key-term reference
  • 86-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 4.1

    Secure network architecture

    Apply secure design principles in network architectures

    20 Qs
    OSI & TCP/IP models by layerSecure protocols: IPSec, TLS, SSHPhysical, logical & micro-segmentationNorth-south vs. east-west trafficWireless, cellular & edge networksSDN, VPC & network monitoring
  2. 4.2

    Securing network components

    Secure network components

    20 Qs
    Firewall types & generationsIDS vs. IPS placementSignature vs. anomaly detectionTransmission media properties802.1X & network access controlEndpoint protection & EDR
  3. 4.3

    Secure communication channels

    Implement secure communication channels according to design

    20 Qs
    Collaboration & conferencing controlsVoIP segmentation & SRTPVPN vs. zero trust network accessBastion hosts & PAMBackhaul & satellite linksThird-party connectivity
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 8 CISSP domains

Sitting the whole exam? Get the Complete CISSP Collection.

Every domain of the exam, including this guide, for $129, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CISSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (4.1–4.3), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 60 practice questions, plus a 86-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 4.0 (13% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 13% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide