Courseiva
hardMultiple ChoiceObjective-mapped

220-1201 Practice Question: Deploy a virtualized environment where each VM…

A company needs to deploy a virtualized environment where each VM must be isolated from others for security reasons, but all VMs share the same physical network. Which virtual networking configuration should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a virtual switch with port groups assigned to different VLANs

VLANs provide network isolation at Layer 2, allowing VMs on the same physical network to be separated logically. This is a common security practice in virtualized environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a virtual switch with port groups assigned to different VLANs

    Why this is correct

    Using a virtual switch with port groups assigned to distinct VLANs is the correct approach for network segmentation in a virtualized environment. Each port group can be configured with a specific VLAN ID, ensuring that virtual machines connected to different port groups are logically isolated at Layer 2. This prevents direct communication between VMs in different VLANs without a router, effectively segmenting traffic and enhancing security and network organization.

  • Configure each VM with a different MAC address

    Why it's wrong here

    Configuring each virtual machine with a different MAC address does not provide any network isolation. While MAC addresses are unique identifiers essential for Layer 2 communication, they do not inherently segment network traffic or prevent VMs on the same broadcast domain from communicating. VMs with different MACs can still freely interact if they reside on the same logical network segment.

  • Use bridged networking for all VMs

    Why it's wrong here

    Utilizing bridged networking for all virtual machines connects them directly to the physical network adapter of the host, placing them on the same network segment as the host and other physical devices. This configuration makes all VMs part of the same broadcast domain, allowing them to communicate freely with each other and the external network without any inherent isolation. It essentially bypasses any virtual network segmentation capabilities.

  • Assign each VM a static IP address from a different subnet

    Why it's wrong here

    Assigning each virtual machine a static IP address from a different subnet, while a Layer 3 segmentation technique, does not provide true network isolation at Layer 2. If all VMs are still connected to the same virtual switch and broadcast domain (e.g., the same VLAN), they can still communicate via a configured default gateway or router that bridges these subnets. Effective isolation requires Layer 2 separation, such as VLANs, to prevent direct communication before Layer 3 routing is even considered.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Go deeper

Related to this question

About these practice questions

One of 972 original 220-1201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.