Study ISC2 CC network security infrastructure: data centers, redundancy, DMZ, VLAN, VPN, micro-segmentation, NAC, IoT, cloud, MSP, and hybrid.
Network security infrastructure is about control placement. CC expects you to recognize the basic purpose of on-premises, segmented, remote-access, cloud, and hybrid controls.
| Area | What it protects |
|---|---|
| Power and HVAC | availability of facilities and equipment |
| Data center or closet controls | physical access and environmental resilience |
| Fire suppression | physical safety and availability |
| Redundancy | availability and fault tolerance |
| DMZ | separates public-facing services from internal networks |
| VLAN | logical segmentation inside networks |
| VPN | protected remote or site-to-site connectivity |
| Micro-segmentation | finer-grained traffic isolation |
| NAC | controls which devices can connect |
| Term | Exam meaning |
|---|---|
| SLA | service-level agreement for availability or service expectations |
| MSP | managed service provider |
| SaaS | software delivered as a service |
| IaaS | infrastructure components delivered as a service |
| PaaS | application platform delivered as a service |
| Hybrid | combination of on-premises and cloud environments |
Network segmentation can protect AI development, testing, and production environments from sensitive data exposure. For CC, think isolation, least privilege, monitoring, and approved data paths.