Network Security

Study ISC2 CC network security: OSI, TCP/IP, ports, threats, IDS/IPS, firewalls, segmentation, NAC, VPNs, cloud, and hybrid.

Network Security is weighted at 24% in the current CC outline. It is the second-largest domain and often separates candidates who can name attacks from candidates who understand basic control placement.

Work this domain in order

  1. Networking Models, Ports, and Applications for OSI, TCP/IP, IPv4, IPv6, Wi-Fi, ports, and application traffic.
  2. Network Threats and Attacks for DDoS, malware, MITM, side-channel, IDS/HIDS/NIDS, antivirus, scanning, firewalls, and IPS.
  3. Network Security Infrastructure for on-premises controls, segmentation, DMZ, VLAN, VPN, micro-segmentation, NAC, IoT, cloud service models, MSPs, and hybrid environments.

Network-security thinking pattern

    flowchart LR
	  A["Asset"] --> P["Path"]
	  P --> T["Threat"]
	  T --> C["Control placement"]
	  C --> M["Monitoring evidence"]

The exam is rarely asking for one magic device. It wants the control at the right point in the path.

In this section

Revised on Monday, June 15, 2026