mediumMultiple ChoiceObjective-mapped
350-701 Practice Question: Designing a secure segmentation strategy for a…
A company is designing a secure segmentation strategy for a three-tier web application. They want to isolate the web, application, and database tiers while allowing only necessary traffic. Which design best achieves defense-in-depth while minimizing complexity?
⚠ Common exam trap
Cisco often tests the misconception that stateful firewalls alone (Option D) or VLANs with ACLs (Option A) provide sufficient segmentation, but the trap is that defense-in-depth requires policy-based, identity-aware controls like SGTs to prevent lateral movement and reduce complexity in multi-tier applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use VRF-Lite with SGTs and enforce policies via Cisco ISE.
VRF-Lite with Security Group Tags (SGTs) and Cisco ISE provides scalable, policy-based segmentation that follows the defense-in-depth principle. VRF-Lite creates separate routing tables for each tier, while SGTs enforce granular, identity-based access control at the network layer, reducing complexity compared to multiple firewalls or ACLs. This design allows necessary traffic between tiers without relying on IP addresses alone, aligning with zero-trust architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place each tier in a separate VLAN and rely on ACLs on the distribution switch.
Why it's wrong here
ACLs alone do not provide sufficient control and are hard to manage.
- ✗
Deploy a dedicated firewall for each tier and connect them in series.
Why it's wrong here
Overly complex and expensive; not a best practice for this scenario.
- ✓
Use VRF-Lite with SGTs and enforce policies via Cisco ISE.
Why this is correct
Allows granular, policy-based segmentation without per-tier firewalls.
- ✗
Place a single stateful firewall between each tier with separate interfaces.
Why it's wrong here
Single firewall creates bottleneck and increases failure risk.
Go deeper
Related to this question
About these practice questions
This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.