SY0-701 VLAN (Virtual Local Area Network) Practice Question
A branch office has users, finance workstations, printers, and IP phones on one flat LAN. After a malware outbreak on a user PC, management wants to limit lateral movement without blocking printing or voice traffic. What should the network team implement?
⚠ Common exam trap
Many candidates confuse 'limiting lateral movement' with 'blocking all east-west traffic,' forgetting that printing and voice require specific peer-to-peer flows that a proxy or full-block would break.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate VLANs for device groups and apply inter-VLAN ACLs that permit only required traffic.
Segmenting devices into separate VLANs (e.g., users, finance, printers, IP phones) and applying inter-VLAN ACLs restricts lateral movement by default while permitting only necessary traffic like printing (TCP 9100) and voice (RTP/UDP 16384-32767). This aligns with the principle of least privilege and zero trust segmentation, preventing malware from spreading across the flat LAN without disrupting critical services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move all devices into one larger subnet and rely on endpoint antivirus for separation.
Why it's wrong here
Enlarging the subnet widens the broadcast domain and leaves every host directly reachable, so lateral movement is unrestricted; antivirus only detects known malware on the endpoint. Endpoint antivirus belongs in a defence-in-depth layer, not as the segmentation control this scenario demands.
- ✓
Create separate VLANs for device groups and apply inter-VLAN ACLs that permit only required traffic.
Why this is correct
Segmenting the flat LAN into VLANs by device role, then enforcing inter-VLAN ACLs that permit only required flows, contains lateral movement while preserving printing and voice. This satisfies management's constraint of restricting spread without disrupting legitimate services.
- ✗
Place all devices behind a single proxy server and block all internal east-west traffic.
Why it's wrong here
A proxy inspects and forwards application traffic; it cannot segment a flat LAN, so east-west traffic between hosts still flows directly and lateral movement remains possible. Proxies suit outbound web control, not internal micro-segmentation, which requires VLANs or firewall-enforced zones.
- ✗
Enable port security on the switch and disable all VLAN tagging to reduce complexity.
Why it's wrong here
Port security restricts MAC addresses per switch port but leaves the flat Layer 2 domain intact, so lateral movement between hosts continues. It suits preventing rogue devices on access ports. Segmenting users, finance, printers and phones into separate VLANs with ACLs is needed here.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Design Principles
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.