Network Security
Study ISC2 CC network security: OSI, TCP/IP, ports, threats, IDS/IPS, firewalls, segmentation, NAC, VPNs, cloud, and hybrid.
Network Security is weighted at 24% in the current CC outline. It is the second-largest domain and often separates candidates who can name attacks from candidates who understand basic control placement.
Work this domain in order
- Networking Models, Ports, and Applications for OSI, TCP/IP, IPv4, IPv6, Wi-Fi, ports, and application traffic.
- Network Threats and Attacks for DDoS, malware, MITM, side-channel, IDS/HIDS/NIDS, antivirus, scanning, firewalls, and IPS.
- Network Security Infrastructure for on-premises controls, segmentation, DMZ, VLAN, VPN, micro-segmentation, NAC, IoT, cloud service models, MSPs, and hybrid environments.
Network-security thinking pattern
flowchart LR
A["Asset"] --> P["Path"]
P --> T["Threat"]
T --> C["Control placement"]
C --> M["Monitoring evidence"]
The exam is rarely asking for one magic device. It wants the control at the right point in the path.
In this section
-
Networking Models, Ports, and Applications
Study ISC2 CC networking basics: OSI model, TCP/IP, IPv4, IPv6, Wi-Fi, ports, protocols, and applications.
-
Network Threats and Attacks
Study ISC2 CC network threats and attacks: DDoS, virus, worm, Trojan, MITM, side-channel, IDS, HIDS, NIDS, IPS, firewalls, and antivirus.
-
Network Security Infrastructure
Study ISC2 CC network security infrastructure: data centers, redundancy, DMZ, VLAN, VPN, micro-segmentation, NAC, IoT, cloud, MSP, and hybrid.
Revised on Monday, June 15, 2026