← ISC2 CC: cybersecurity foundations in practice
04 / 5 · 40 MIN

Networks, cloud, and boundaries

Interpret layers and paths without assuming automatic isolation.

Concept and mechanism

Troubleshooting improves when each observation is tied to the right layer. If TCP connects but the client rejects the certificate, investigate TLS validation: identity, trust, and validity. Reopening the same port does not necessarily resolve the observed error. Similarly, segmentation needs controls on actual paths. Two VLANs separate broadcast domains but may communicate through permitted routing. An inter-zone rule should reflect needed flows and block unauthorized ones. In dual stack, IPv4 and IPv6 need assessment; restricting one address family does not fix excessive permission in the other. DNS and names do not replace access rules.

Guided application

In a fictional SaaS ticket service, the provider maintains the application while the company still decides users, permissions, and sharing. Record the model and contract before assigning responsibilities. IaaS, PaaS, and SaaS distribute tasks differently. Elasticity adjusts capacity to demand; it does not prove instances survive regional loss or that no residual costs exist. An older device without an immediate patch may require restricted communication, monitoring, and a replacement plan. That measure reduces exposure without making the device patched. To validate a network change, rehearse legitimate communication and denial of the unwanted path. One successful connection from administration does not demonstrate guests were blocked.

IN PRACTICE

Different guest VLAN + permitted routing to administration = access separation remains incomplete.

Common pitfalls

Open port as valid TLS; VLAN as complete isolation; IPv4 as IPv6 coverage; SaaS as no responsibility.

Related topics: Security principles and conduct · Governance, continuity, and awareness · Identity and access lifecycle

Take this idea with you

Check the actual path and responsibilities of the model in use.

Create account

Reference: Zero trust architecture · CC examination outline effective 2026-09-01; PDF v01/2026