Courseiva
Network Security →hardMultiple Choice

N10-009 Network Security Practice Question

A security engineer is designing a network segmentation strategy for a data center. The requirement is to isolate traffic between virtual machines on the same hypervisor so that even if one VM is compromised, it cannot sniff traffic from other VMs. Which technology should the engineer implement to meet this requirement?

⚠ Common exam trap

The trap here is assuming that VLANs alone provide sufficient isolation, but VMs on the same hypervisor can often bypass VLAN boundaries through the virtual switch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsegmentation

Microsegmentation enforces security policies at the workload level, often using virtual firewalls or software-defined networking. It isolates VMs on the same hypervisor by controlling traffic at the virtual NIC, preventing lateral movement and sniffing even within the same host. VLANs, PVLANs, and NAT operate at different layers and do not provide the same granular, per-VM isolation required in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Private VLANs (PVLANs)

    Why it's wrong here

    Private VLANs isolate ports within a VLAN at Layer 2, preventing communication between isolated ports. However, PVLANs are typically configured on physical switches and may not extend into virtual switch environments without specific support. The scenario focuses on virtual machines on the same hypervisor, where a virtual firewall or microsegmentation is more appropriate. PVLANs alone do not provide the granular, per-VM enforcement required here.

  • ✓

    Microsegmentation

    Why this is correct

    Microsegmentation creates fine-grained security policies around individual workloads, including VMs on the same hypervisor. It enforces traffic filtering at the virtual NIC level, preventing a compromised VM from sniffing or communicating with other VMs unless explicitly allowed. This directly meets the requirement to isolate intra-hypervisor traffic and limit lateral movement, which traditional VLANs cannot achieve within a single host.

  • ✗

    VLAN tagging

    Why it's wrong here

    VLAN tagging separates traffic at Layer 2 by adding tags to frames, but VMs on the same hypervisor often share a virtual switch that can route or bridge between VLANs. An attacker with access to the hypervisor or a VM with promiscuous mode could still capture traffic. VLAN tagging alone does not provide the per-VM isolation needed to prevent sniffing between VMs on the same host.

  • ✗

    Network address translation (NAT)

    Why it's wrong here

    NAT translates IP addresses between networks, typically to conserve public addresses or hide internal topology. It does not isolate traffic between VMs on the same hypervisor; VMs on the same virtual network can still communicate directly. NAT operates at Layer 3 and does not prevent a compromised VM from sniffing or attacking neighboring VMs, so it fails to meet the isolation requirement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every N10-009 question from scratch — 472 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.