Close the merger bypass without breaking required traffic

A hands-on CISSP lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll CISSP practice

Certification
CISSP
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
9

The brief

Edit zone-plan.json. links is a complete map of link IDs to true/false; all required links must remain enabled. policies contains every guard {id,defaultAction,rules}. Rules use {id,sources,targets,transport,ports,action}; transport is tcp, udp or tcp+udp and ports is an inclusive integer [low,high] within 0..65535. The first matching rule decides; unmatched traffic uses defaultAction. A connection succeeds if any enabled directed path permits it at every guard. Endpoint nodes never forward; identities do not change in transit. Keep every listed request interval in its applicable stage, deny all other new connections between distinct endpoints and use deny defaults on every guard, even an unused one. Report enabledLinks across the whole plan, plus approvedPortTuples and unauthorizedPortTuples keyed before/after. Count distinct (source,target,transport,port) tuples, never paths; null is allowed only for an unfinished report. An exact report is evidence, not a substitute for a safe working policy.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • Complete typed link, ordered rule and report records
  • Every baseline attachment remains enabled
  • Every declared boundary has a fail-closed default
  • All web and database contract intervals work in both inventories
  • Required TCP and UDP DNS intervals remain reachable
  • Management requests remain within their supplied contract
  • Untrusted origins have no extra connection through any path
  • No modeled origin can initiate any unapproved port tuple
  • Report matches actual unique connection tuples and enabled links

Where this sits in the CISSP blueprint

Domain
Communication and Network Security
Objective
Secure Network Architecture
Skill
Segmentation, Traffic and Trust Boundaries

Part of CISSP preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.