Courseiva
Networking →easyMultiple Choice

220-1101 Networking Practice Question

A network technician is configuring a small office network. The office has two departments: Sales and Accounting. The technician needs to ensure that devices in Sales cannot communicate with devices in Accounting, but both departments must be able to access the internet. The network uses a single router and one managed switch. Which of the following should the technician configure on the switch?

⚠ Common exam trap

CompTIA often tests the misconception that VLANs require a router for any communication, but the trap here is that the question only requires internet access, not inter-department communication, so VLANs alone on the switch suffice to isolate Sales from Accounting while both can reach the internet via the router's default gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLANs

VLANs (Virtual Local Area Networks) allow the technician to logically segment the switch into separate broadcast domains. By placing Sales devices in one VLAN and Accounting devices in another, inter-VLAN communication is blocked at Layer 2, while both VLANs can still access the internet through the single router (which performs inter-VLAN routing if configured, but here only internet access is needed, so the router can simply provide default gateway connectivity without routing between VLANs).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port mirroring

    Why it's wrong here

    Port mirroring, also known as SPAN, copies packets traversing a switch port and forwards them to a designated monitoring port for analysis by tools like Wireshark or an IDS. This is a passive observation technique; it does not alter the forwarding path or make any decisions about which frames can reach which destinations. As a result, port mirroring cannot enforce isolation between departments because it merely duplicates traffic for inspection while leaving the original switched traffic untouched. Without a separate broadcast domain or filtering rule, hosts on different departments would still communicate directly at Layer 2.

  • ✓

    VLANs

    Why this is correct

    VLANs partition a physical switch into multiple virtual LANs, each forming its own broadcast domain, and insert 802.1Q tags into Ethernet frames to identify membership. Devices assigned to different VLANs cannot communicate directly at Layer 2 because each VLAN's forwarding table is isolated; the switch will not forward frames between VLANs without an external router or a Layer 3 switch configured for inter-VLAN routing. This meets the department isolation requirement while allowing a router to forward only the necessary traffic for internet access, preserving security and controlling broadcast traffic. By segmenting the network logically, VLANs also simplify moves and changes without rewiring.

  • ✗

    Link aggregation

    Why it's wrong here

    Link aggregation, typically implemented via LACP or EtherChannel, bundles multiple physical Ethernet links into a single logical connection to scale bandwidth beyond one interface speed and provide failover if a member link fails. Traffic distribution across the member links is determined by a hash algorithm based on source/destination MAC or IP addresses, not by policy or department membership. While this can improve performance and resilience for the office network, it does nothing to separate broadcast domains or restrict communication between groups. Because all aggregated links remain in the same Layer 2 domain, hosts in different departments still see each other's broadcasts and can directly exchange frames.

  • ✗

    Spanning Tree Protocol

    Why it's wrong here

    Spanning Tree Protocol (STP) runs on switches and bridges to eliminate Layer 2 loops by placing redundant links in a blocking state using the exchange of Bridge Protocol Data Units (BPDUs). STP elects a root bridge and determines the best path to it, disabling any alternative paths that would cause broadcast storms or MAC address table instability. Although this ensures network reliability in a redundant topology, it has no concept of user groups or traffic policy; the logical topology it creates still allows all devices in the same broadcast domain to communicate. Therefore, STP cannot provide department-level isolation and is purely a loop-prevention mechanism, not a segmentation tool.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.