Courseiva
Security Architecture →mediumMultiple Choice

SY0-701 VLAN (Virtual Local Area Network) Practice Question

A branch office has users, finance workstations, printers, and IP phones on one flat LAN. After a malware outbreak on a user PC, management wants to limit lateral movement without blocking printing or voice traffic. What should the network team implement?

⚠ Common exam trap

Many candidates confuse 'limiting lateral movement' with 'blocking all east-west traffic,' forgetting that printing and voice require specific peer-to-peer flows that a proxy or full-block would break.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate VLANs for device groups and apply inter-VLAN ACLs that permit only required traffic.

Segmenting devices into separate VLANs (e.g., users, finance, printers, IP phones) and applying inter-VLAN ACLs restricts lateral movement by default while permitting only necessary traffic like printing (TCP 9100) and voice (RTP/UDP 16384-32767). This aligns with the principle of least privilege and zero trust segmentation, preventing malware from spreading across the flat LAN without disrupting critical services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move all devices into one larger subnet and rely on endpoint antivirus for separation.

    Why it's wrong here

    Enlarging the subnet widens the broadcast domain and leaves every host directly reachable, so lateral movement is unrestricted; antivirus only detects known malware on the endpoint. Endpoint antivirus belongs in a defence-in-depth layer, not as the segmentation control this scenario demands.

  • ✓

    Create separate VLANs for device groups and apply inter-VLAN ACLs that permit only required traffic.

    Why this is correct

    Segmenting the flat LAN into VLANs by device role, then enforcing inter-VLAN ACLs that permit only required flows, contains lateral movement while preserving printing and voice. This satisfies management's constraint of restricting spread without disrupting legitimate services.

  • ✗

    Place all devices behind a single proxy server and block all internal east-west traffic.

    Why it's wrong here

    A proxy inspects and forwards application traffic; it cannot segment a flat LAN, so east-west traffic between hosts still flows directly and lateral movement remains possible. Proxies suit outbound web control, not internal micro-segmentation, which requires VLANs or firewall-enforced zones.

  • ✗

    Enable port security on the switch and disable all VLAN tagging to reduce complexity.

    Why it's wrong here

    Port security restricts MAC addresses per switch port but leaves the flat Layer 2 domain intact, so lateral movement between hosts continues. It suits preventing rogue devices on access ports. Segmenting users, finance, printers and phones into separate VLANs with ACLs is needed here.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.