SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CC · Domain 4

Networking and Cloud Security Concepts practice questions

Networking and Cloud Security Concepts is worth 22% of the CC exam — the 2nd-heaviest of the 5 domains. Network security, network security architecture, and cloud security. Official weighting 21.3%. 6 fully worked examples are further down this page, answers included.

Exam weight
22%
the 2nd-heaviest of the 5 domains
Questions
60
across 3 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Networking and Cloud Security Concepts questions, fully explained

Questions from the CC bank mapped to domain 4, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CC practice page.

Question 1Networking and Cloud Security Concepts

Which OSI layer is responsible for logical addressing and routing packets between networks using IP addresses?

Choose one.

  • a
    Layer 2, Data Link

    The Data Link layer handles physical MAC addressing and frame delivery within a local network segment, not routing between networks.

  • b
    Layer 4, Transport

    The Transport layer manages end-to-end delivery with TCP and UDP and uses port numbers, not IP routing.

  • c
    Layer 7, Application

    The Application layer provides network services to user applications, such as HTTP and DNS, and does not perform packet routing.

  • d
    Layer 3, Network Correct

    The Network layer handles logical IP addressing and routing, moving packets between different networks. Routers operate at this layer.

The concept

Each OSI layer has a distinct addressing and delivery responsibility. The Network layer (Layer 3) owns logical addressing and routing.

Why that’s the answer

IP addresses are logical addresses that identify hosts across interconnected networks. Layer 3, the Network layer, uses these addresses to route packets from a source network to a destination network. Routers are the classic Layer 3 device.

How to reason it out
  1. Identify the type of address in the question: IP addresses are logical addresses.
  2. Map logical addressing and inter-network routing to Layer 3, the Network layer.
  3. Contrast with Layer 2, which uses physical MAC addresses for delivery inside a single network segment.

Exam tip: IP addressing and routing belong to Layer 3, the Network layer, where routers operate.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

Question 2Networking and Cloud Security Concepts

A network switch forwards frames to devices based on their MAC addresses. At which OSI layer does this function operate?

Choose one.

  • a
    Layer 1, Physical

    The Physical layer deals with raw bits, cables, and signals. A device that reads MAC addresses is making decisions above the Physical layer.

  • b
    Layer 3, Network

    Layer 3 uses IP addresses for routing between networks. MAC-based forwarding within a local network happens below it.

  • c
    Layer 4, Transport

    The Transport layer handles TCP and UDP segments and port numbers, not frame forwarding by MAC address.

  • d
    Layer 2, Data Link Correct

    The Data Link layer uses MAC addresses to deliver frames within a local network, which is exactly what a switch does.

The concept

Network devices map to OSI layers by the addresses they use: hubs to Layer 1, switches to Layer 2, routers to Layer 3.

Why that’s the answer

MAC addresses are physical hardware addresses used at Layer 2, the Data Link layer. A switch learns which MAC address lives on which port and forwards frames accordingly, making it the classic Layer 2 device.

How to reason it out
  1. Note the address type in the question: MAC addresses are hardware addresses.
  2. Map MAC addressing and frame delivery to Layer 2, the Data Link layer.
  3. Remember the device-to-layer pairs: switch at Layer 2, router at Layer 3.

Exam tip: Switches and MAC addresses operate at Layer 2, the Data Link layer.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

Question 3Networking and Cloud Security Concepts

TCP, UDP, and port numbers operate at which layer of the OSI model?

Choose one.

  • a
    Layer 3, Network

    Layer 3 handles IP addressing and routing. TCP and UDP sit one layer above it.

  • b
    Layer 5, Session

    The Session layer manages establishing and tearing down communication sessions, not TCP, UDP, or ports.

  • c
    Layer 7, Application

    The Application layer holds protocols like HTTP and DNS that run on top of TCP or UDP, not the transport protocols themselves.

  • d
    Layer 4, Transport Correct

    The Transport layer provides end-to-end delivery using TCP (connection-oriented, reliable) and UDP (connectionless), addressed by port numbers.

The concept

The Transport layer (Layer 4) provides end-to-end communication between hosts using TCP and UDP, with port numbers identifying specific services.

Why that’s the answer

TCP and UDP are the two main transport protocols. TCP provides reliable, connection-oriented delivery, while UDP is faster but connectionless. Both use port numbers to direct traffic to the right service on a host, and all of this happens at Layer 4.

How to reason it out
  1. Recall that TCP and UDP are transport protocols by definition.
  2. Associate port numbers with the Transport layer, since ports identify which service on a host should receive the traffic.
  3. Place this at Layer 4, above IP routing at Layer 3 and below application protocols at Layer 7.

Exam tip: TCP, UDP, and ports all live at Layer 4, the Transport layer.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

Question 4Networking and Cloud Security Concepts

How long is an IPv4 address?

Choose one.

  • a
    64 bits

    Neither IP version uses 64-bit addresses. IPv4 is 32 bits and IPv6 is 128 bits.

  • b
    128 bits

    128 bits is the length of an IPv6 address, not an IPv4 address.

  • c
    32 bits Correct

    IPv4 addresses are 32 bits long, usually written as four decimal numbers separated by dots, such as 192.168.1.1.

  • d
    256 bits

    No IP addressing scheme uses 256-bit addresses. This is larger than even IPv6.

The concept

IPv4 uses 32-bit addresses, giving roughly 4.3 billion possible addresses, which proved too few for the modern internet.

Why that’s the answer

An IPv4 address is 32 bits, conventionally shown as four octets in dotted-decimal notation like 10.0.0.1. Each octet is 8 bits, and four octets make 32 bits total.

How to reason it out
  1. Recall the dotted-decimal format of IPv4: four numbers separated by dots.
  2. Each number is one octet of 8 bits, so four octets equal 32 bits.
  3. Contrast with IPv6, which uses 128-bit addresses written in hexadecimal.

Exam tip: IPv4 = 32 bits, IPv6 = 128 bits. This pairing is a frequent exam fact.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

Question 5Networking and Cloud Security Concepts

What was the primary reason IPv6 was developed?

Choose one.

  • a
    To make wireless networks faster

    IPv6 is an addressing protocol, not a wireless performance technology. Wi-Fi speed is unrelated to the IP version in use.

  • b
    To replace TCP with a more reliable protocol

    IPv6 replaces IPv4 at the Network layer. TCP continues to operate unchanged at the Transport layer on top of either IP version.

  • c
    The exhaustion of available IPv4 addresses Correct

    The 32-bit IPv4 space of about 4.3 billion addresses ran out as the internet grew, so IPv6 introduced a vastly larger 128-bit address space.

  • d
    To eliminate the need for firewalls

    IPv6 does not remove the need for traffic filtering. Firewalls remain essential regardless of IP version.

The concept

IPv6 was created because the internet outgrew the IPv4 address space. Its 128-bit addresses provide an effectively inexhaustible supply.

Why that’s the answer

IPv4's 32-bit space allows roughly 4.3 billion addresses, which was depleted by the explosion of internet-connected devices. IPv6 solves this with 128-bit addresses, providing an astronomically larger pool.

How to reason it out
  1. Recall that IPv4 addresses are 32 bits, limiting the total to about 4.3 billion.
  2. Recognize that the growth of devices exhausted that supply, which is called IPv4 address exhaustion.
  3. Conclude that IPv6's 128-bit addressing was the designed remedy for the shortage.

Exam tip: IPv6 exists primarily because IPv4 addresses ran out; its 128-bit space solves the shortage.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

Question 6Networking and Cloud Security Concepts

Which well-known port is used by HTTPS for encrypted web traffic?

Choose one.

  • a
    Port 80

    Port 80 is used by HTTP, the unencrypted version of web traffic.

  • b
    Port 25

    Port 25 is used by SMTP for transferring email between mail servers.

  • c
    Port 443 Correct

    HTTPS uses port 443 to carry web traffic encrypted with TLS, protecting confidentiality and integrity.

  • d
    Port 22

    Port 22 is used by SSH for secure remote administration, not web browsing.

The concept

Well-known ports map standard services to standard numbers so clients know where to reach them. HTTPS is assigned port 443.

Why that’s the answer

HTTPS is HTTP protected by TLS encryption, and it is assigned well-known port 443. Its unencrypted counterpart HTTP uses port 80, which is why browsers and firewalls treat 80 and 443 as the two web ports.

How to reason it out
  1. Identify the service: HTTPS is encrypted web traffic.
  2. Recall the web port pair: HTTP on 80, HTTPS on 443.
  3. Eliminate ports belonging to other services: 22 for SSH and 25 for SMTP.

Exam tip: HTTP = 80 (insecure), HTTPS = 443 (secure). Know the common port pairs cold.

Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs — the lesson that teaches this.

What CC domain 4 tests, topic by topic

The official exam guide breaks Networking and Cloud Security Concepts into 3 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CC practice questions per topic in Networking and Cloud Security Concepts
TopicWhat it coversQuestions
Understand network securityOfficial CC sub-domain (Networking and Cloud Security, Sept-2026 outline). Networking concepts (OSI and TCP/IP models, IPv4/IPv6, VPN); firewalls (ports, applications); wireless (Wi-Fi, Bluetooth); and embedded systems (Industrial Control Systems) and the Internet of Things (IoT).20
Understand network security architectureOfficial CC sub-domain. Network segmentation (firewall zones, VLANs, micro-segmentation); Defense in Depth; and Zero Trust (ZT).20
Understand cloud securityOfficial CC sub-domain. Cloud characteristics (broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling); service models; deployment models; and the shared security (responsibility) model.20
Total60

Revise Networking and Cloud Security Concepts before you drill it

Other CC domains

Networking and Cloud Security Concepts: your questions

Networking and Cloud Security Concepts is domain 4 of the CC exam guide and carries 22% of the scored content — the 2nd-heaviest of the 5 domains. On a 100-question paper that works out to roughly 22 questions, though ISC2 does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CC exam guide.