mediumMultiple Choice
CAS-004 Practice Question: A security architect is reviewing the network…
A security architect is reviewing the network segmentation of a healthcare organization that must comply with HIPAA. The current flat network allows all devices to communicate. Which segmentation approach provides the best balance of security and manageability?
⚠ Common exam trap
It's easy for candidates to confuse 'segmentation' with 'isolation' and choose Option B (every device its own VLAN) thinking it maximizes security, but they overlook the manageability nightmare and the fact that HIPAA requires authorized access between systems for treatment, payment, and operations (TPO).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segment using VLANs and ACLs to limit traffic to necessary flows
VLANs logically segment the flat network into separate broadcast domains, and ACLs applied at the Layer 3 boundary (e.g., on the switch virtual interface or router) enforce least-privilege access by permitting only necessary traffic flows between segments. This approach meets HIPAA's technical safeguard requirements (45 CFR § 164.312(a)(1)) for access control and integrity without the operational overhead of physical separation or the security risk of a single DMZ.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a physical air gap between all systems
Why it's wrong here
Air-gapping every system eliminates the connectivity HIPAA operations require, such as e-prescribing and records exchange, and cannot scale across a hospital estate. It is tempting because physical separation gives the strongest isolation, and it would be correct for an isolated research or backup segment with no operational network dependency.
- ✗
Assign each device its own VLAN with no inter-VLAN routing
Why it's wrong here
Per-device VLANs with no inter-VLAN routing break the clinical workflows HIPAA-covered entities depend on, since EHR, imaging and pharmacy systems must exchange data. It is tempting because full isolation maximises containment, and it would suit a lab or OT enclave where no cross-system traffic is legitimate.
- ✓
Segment using VLANs and ACLs to limit traffic to necessary flows
Why this is correct
VLANs with ACLs enforce least-privilege east-west traffic filtering at Layer 3, isolating regulated ePHI systems from general devices while remaining operationally manageable without per-host agents. This satisfies HIPAA's access-control and segmentation expectations, unlike a flat network where any compromised device reaches every system.
- ✗
Place all critical systems in a single DMZ subnet
Why it's wrong here
A single DMZ subnet groups all critical systems into one segment, so a compromise in any one host exposes the rest, and it does not separate clinical, administrative and medical-device traffic as HIPAA expects. Microsegmentation or tiered internal zones would be correct, isolating systems by function and data sensitivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.