CISSP Domain 4: OSI, IPsec, TLS & VoIP Security
On the CISSP, secure-protocol questions come down to one move: name the network layer, then match the protocol to the requirement. This Domain 4 deep-dive builds the OSI seven-layer and TCP/IP four-layer models, then walks the heavyweight secure protocols and exactly when each one is the right answer. With Fatima, Erica, Liam, and Mei, we cover the network-security foundations behind 13% of the current exam, and the question-reading habits that turn ‘BEST’ and ‘MOST’ scenarios into quick, defensible picks.
In this video:
- The OSI 7 layers and TCP/IP 4 layers, plus encapsulation and PDUs (bits, frames, packets, segments)
- IPsec at Layer 3: why AH gives integrity but no confidentiality, and ESP gives both
- Transport mode vs tunnel mode, and which one a site-to-site VPN actually uses
- TLS 1.3: forward secrecy, the cleanup of weak crypto, and the faster handshake
- Which protocols are deprecated (SSL, TLS 1.0, TLS 1.1) and how the exam traps you with them
- Securing VoIP end to end: SIP with TLS, RTP secured by SRTP, and the threat names to know
The next video in the series moves into secure network components, the firewalls and segmentation that put these protocols to work. Anchored to the (ISC)2 CISSP Detailed Content Outline effective April 15, 2024.
▶ Watch next: CISSP Domain 4: Segmentation & Zero Trust Explained https://www.youtube.com/watch?v=fBVPDnby_fg
📺 Full playlist: CISSP (2026) v2 https://www.youtube.com/playlist?list=PLlIAFxS2964_K3g6WysWnLpifoxilduGi
Chapters
- 0:00 The Protocol That Failed the Audit
- 3:20 Seven Layers, One Mental Map
- 5:58 Four Layers and the Encapsulation Trick
- 8:29 Reading a Layer Question Fast
- 10:58 IPsec at Layer Three: AH vs ESP
- 13:35 Transport Mode vs Tunnel Mode
- 16:03 TLS and the 1.3 Cleanup
- 18:42 When the Exam Says 'Deprecated'
- 21:22 Securing the VoIP Call
- 23:56 Think Like a Manager
- 26:29 Quiz Time
- 30:15 Key Takeaways
On the CISSP, secure-protocol questions come down to one move: name the network layer, then match the protocol to the requirement. This Domain 4 deep-dive builds the OSI seven-layer and TCP/IP four-layer models, then walks the...
Key Topics
- The Protocol That Failed the Audit
- Seven Layers, One Mental Map
- Four Layers and the Encapsulation Trick
- Reading a Layer Question Fast
- IPsec at Layer Three: AH vs ESP
- Transport Mode vs Tunnel Mode
- TLS and the 1.3 Cleanup
- When the Exam Says 'Deprecated'