hardMultiple Choice
200-201 Practice Question: Is designing a segmented network to protect a…
A network engineer is designing a segmented network to protect a sensitive database. The database must be accessible only from a specific application server. Which security concept best describes this design?
⚠ Common exam trap
Cisco often tests least privilege by framing it as a network segmentation or access control question, and the trap here is confusing it with defense in depth because both involve multiple layers, but least privilege specifically focuses on granting only the necessary permissions rather than layering controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Least privilege, is correct because the design restricts access to the sensitive database to only the specific application server that requires it. This principle dictates that users, processes, or systems should be granted the minimum permissions necessary to perform their functions, thereby reducing the attack surface. By implementing network access control lists (ACLs) or firewall rules that permit traffic solely from the application server's IP address to the database port, the engineer enforces least privilege at the network layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls; this design instead restricts database reachability to one application server, which is microsegmentation. Defense in depth is tempting because segmentation is a layer within it, and it would be correct if the scenario described several overlapping controls rather than a single access restriction.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a single task across multiple people to prevent fraud, so it does not describe restricting database access to one application server. It is tempting because both are access-control principles, but it would be the answer where no individual can complete a critical transaction alone.
- ✗
Weakest link
Why it's wrong here
The weakest link describes how overall security is limited by the most vulnerable component, not restricting database reachability to one application server. It is tempting because both concern exposure, but it would be correct when identifying the component that undermines an otherwise strong control set.
- ✓
Least privilege
Why this is correct
Least privilege grants each subject only the access required for its function. Restricting database reachability to one specific application server, and denying all other hosts, enforces exactly that minimal access, satisfying the segmentation constraint in the scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.