Courseiva
Question 58 of 464
Network ImplementationmediumMultiple ChoiceObjective-mapped

N10-009 Network Implementation Practice Question

A network engineer needs to segment a single physical switch into multiple broadcast domains to improve security and reduce traffic. Which technology should be implemented?

⚠ Common exam trap

CompTIA often tests the distinction between VLANs (which create broadcast domains) and VTP (which only propagates VLAN information), leading candidates to confuse configuration management with actual segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Virtual LAN (VLAN)

A VLAN (Virtual LAN) segments a physical switch into multiple isolated broadcast domains at Layer 2. By assigning ports to different VLANs, broadcast traffic is confined to each VLAN, improving security and reducing unnecessary traffic. This directly meets the requirement without requiring additional hardware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spanning Tree Protocol (STP)

    Why it's wrong here

    Spanning Tree Protocol (STP) is a Layer 2 protocol designed to prevent switching loops in redundant network topologies by intelligently blocking redundant paths. It ensures that only one active path exists between any two network devices, thereby avoiding broadcast storms, MAC address table instability, and multiple frame copies. STP's role is solely to manage redundant links for loop prevention, not to logically segment a switch into multiple broadcast domains.

    When this WOULD be correct

    A question asking which protocol prevents bridging loops in a redundant switched network would have STP as the correct answer, e.g., 'Which technology ensures a loop-free topology in a network with redundant switches?'

  • Virtual LAN (VLAN)

    Why this is correct

    A Virtual LAN (VLAN) is a logical grouping of network devices that allows a single physical switch to be segmented into multiple distinct broadcast domains. By assigning specific switch ports or even hosts to different VLANs, broadcast traffic originating within one VLAN is strictly confined to only the devices belonging to that same VLAN. This effectively isolates network segments, significantly improving security, reducing unnecessary network traffic, and enhancing network performance without requiring additional physical switches.

  • VLAN Trunking Protocol (VTP)

    Why it's wrong here

    VLAN Trunking Protocol (VTP) is a Cisco proprietary protocol designed to manage and synchronize VLAN configurations across multiple switches within a single VTP domain. Its primary function is to propagate VLAN changes, such as creation, deletion, or renaming, from a VTP server to client switches, ensuring consistent VLAN definitions across the network. However, VTP itself does not create or segment broadcast domains; it merely facilitates the administrative management of existing or newly defined VLANs.

  • Access Control List (ACL)

    Why it's wrong here

    An Access Control List (ACL) is a set of rules configured on a router or Layer 3 switch to filter network traffic based on criteria such as source/destination IP addresses, port numbers, or protocols. While ACLs are crucial for network security and traffic management by permitting or denying specific packets, they operate at Layer 3 and above in the OSI model. They do not segment a network into separate broadcast domains, which is fundamentally a Layer 2 function.

    When this WOULD be correct

    A question asking 'Which technology can be used to restrict traffic between two subnets on a router?' would make ACLs correct, as they filter packets based on rules.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Virtual LAN (VLAN)Correct answer

Why this is correct

A Virtual LAN (VLAN) is a logical grouping of network devices that allows a single physical switch to be segmented into multiple distinct broadcast domains. By assigning specific switch ports or even hosts to different VLANs, broadcast traffic originating within one VLAN is strictly confined to only the devices belonging to that same VLAN. This effectively isolates network segments, significantly improving security, reducing unnecessary network traffic, and enhancing network performance without requiring additional physical switches.

Spanning Tree Protocol (STP)Wrong answer — click to see why

Why this is wrong here

STP prevents loops in a network topology but does not segment a switch into multiple broadcast domains; it operates at Layer 2 to manage redundant paths, not to create separate broadcast domains.

★ When this WOULD be the correct answer

A question asking which protocol prevents bridging loops in a redundant switched network would have STP as the correct answer, e.g., 'Which technology ensures a loop-free topology in a network with redundant switches?'

Why candidates choose this

Candidates may confuse STP's role in managing network traffic with segmentation, or think that breaking a network into segments involves loop prevention.

Access Control List (ACL)Wrong answer — click to see why

Why this is wrong here

ACLs filter traffic based on IP addresses or protocols but do not segment a switch into multiple broadcast domains; they operate at Layer 3/4, not Layer 2.

★ When this WOULD be the correct answer

A question asking 'Which technology can be used to restrict traffic between two subnets on a router?' would make ACLs correct, as they filter packets based on rules.

Why candidates choose this

Candidates may confuse traffic filtering (ACLs) with traffic isolation (VLANs), thinking that controlling traffic flow achieves segmentation.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.