Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A security engineer is implementing network segmentation to isolate a PCI DSS environment from the corporate network. The engineer plans to use VLANs and a firewall. Which TWO of the following are essential to ensure that the segmentation is effective and compliant? (Choose two.)

⚠ Common exam trap

The trap here is focusing on additional security controls like IPS or DAI as segmentation mechanisms, when the core requirements are firewall rule sets and VLAN configuration to prevent cross-VLAN traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement 802.1Q VLAN tagging on all switch ports that connect to the PCI environment and ensure that native VLANs are not used on trunk ports.

Effective network segmentation for PCI DSS requires both Layer 3 access control and Layer 2 isolation. A default-deny firewall rule between the PCI VLAN and other networks ensures that only necessary traffic is allowed. Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks that could bypass segmentation. Together, these controls establish a strong boundary. Other measures like DAI, IPS, and PVLANs enhance security but are not essential for the segmentation itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement 802.1Q VLAN tagging on all switch ports that connect to the PCI environment and ensure that native VLANs are not used on trunk ports.

    Why this is correct

    Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks, where an attacker could send double-tagged frames to access another VLAN. This ensures that the segmentation at Layer 2 is robust and that traffic cannot inadvertently cross VLAN boundaries.

  • ✗

    Use private VLANs (PVLANs) to isolate hosts within the PCI VLAN from each other.

    Why it's wrong here

    Private VLANs can provide additional micro-segmentation within a VLAN, but they are not a requirement for basic network segmentation between the PCI environment and the corporate network. The essential elements are firewall rules and VLAN tagging to prevent cross-VLAN traffic. PVLANs address intra-VLAN isolation, which is a different concern.

  • ✗

    Deploy a dedicated intrusion prevention system (IPS) on the PCI VLAN to monitor all traffic.

    Why it's wrong here

    An IPS can detect and block malicious traffic, but it does not create or enforce segmentation. Segmentation is achieved through network design and access controls. An IPS is a monitoring and prevention tool that complements segmentation but is not essential for establishing the isolation itself.

  • ✗

    Enable dynamic ARP inspection (DAI) and DHCP snooping on all VLANs to prevent IP spoofing.

    Why it's wrong here

    While DAI and DHCP snooping are valuable security measures to prevent ARP spoofing and rogue DHCP servers, they are not essential for achieving network segmentation between VLANs. The primary controls for segmentation are firewall rules and VLAN configuration. These features add defense in depth but do not directly enforce isolation.

  • ✓

    Configure the firewall to deny all traffic between the PCI VLAN and other VLANs by default, allowing only explicitly required flows.

    Why this is correct

    A default-deny posture on the firewall ensures that no unauthorized traffic can traverse between the PCI environment and other networks. Only necessary traffic, such as specific management or application flows, should be permitted. This is a fundamental requirement for effective segmentation and helps meet PCI DSS network segmentation controls.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.