An organization has separate VLANs for the HR and Finance departments. Both VLANs use a single Layer 3 switch to route between them. The HR department needs access to a shared printer located in the Finance VLAN, but all other traffic between the VLANs should be blocked. Which of the following should be configured?
Configuring an Access Control List (ACL) on the Layer 3 switch is the most effective and secure method to permit specific traffic between the HR and Finance VLANs. Since the Layer 3 switch performs inter-VLAN routing, it can inspect packets as they traverse between these segmented networks. An ACL can be precisely crafted to allow only the necessary printer-related protocols (e.g., TCP port 9100, SMB) from the HR VLAN to the printer's IP address in the Finance VLAN, while implicitly denying all other traffic.
Why this answer
An ACL on the Layer 3 switch can filter inter-VLAN traffic at the routed interface (SVI or routed port). By permitting only the HR subnet’s traffic to the printer’s IP address and denying all other inter-VLAN traffic, you meet the requirement of selective access while blocking everything else. This is the standard method for policy-based segmentation between VLANs.
Exam trap
The trap here is that candidates often think placing the printer in the same VLAN or creating a dedicated VLAN solves the problem, but they overlook that ACLs are the precise tool for granular, policy-based filtering between VLANs on a Layer 3 switch.
Why the other options are wrong
Placing the printer in the HR VLAN would allow HR devices to access it without routing, but it would not block other traffic between VLANs, and the printer would lose access to Finance resources if needed.
Creating a separate VLAN for the printer does not solve the requirement to permit only HR-to-printer traffic while blocking all other inter-VLAN traffic; it would still require routing and ACLs to control access, and it adds unnecessary complexity.