easymultiple choiceObjective-mapped

An office wants finance workstations separated from general user PCs, but employees still need to print to a shared printer and access one accounting application. Which change best supports this?

Question 1easymultiple choice
Full question →

An office wants finance workstations separated from general user PCs, but employees still need to print to a shared printer and access one accounting application. Which change best supports this?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Place all systems on one VLAN and rely on strong passwords.

Strong passwords do not provide network separation, so a compromise could spread more easily across the office.

B

Best answer

Move finance systems to a separate VLAN or subnet and allow only required traffic through filtering rules.

This is the best choice because it separates finance systems from general users while still allowing approved services like printing and application access. VLANs or subnets reduce lateral movement, and firewall or ACL rules limit communication to only what is needed. That supports least privilege at the network layer.

C

Distractor review

Put the printer in a different building to make it more secure.

Physical distance does not meaningfully solve the access-control problem and would create unnecessary operational complexity.

D

Distractor review

Enable screen lock timers on the finance PCs and keep the network flat.

Screen locks help endpoint security, but they do not isolate finance traffic from other internal users or devices.

Common exam trap

Common exam trap: an active trunk can still block the VLAN you need

A trunk being up does not prove every VLAN is crossing it. Check allowed VLAN lists, native VLAN mismatch, VLAN existence and access-port assignment.

Technical deep dive

How to think about this question

VLAN questions usually combine access-port and trunking clues. The key is to identify whether the issue is local to one switchport, caused by the trunk, or caused by the VLAN not existing where it needs to exist.

KKey Concepts to Remember

  • Access ports place end devices into a single VLAN.
  • Trunk ports carry multiple VLANs between switches.
  • Allowed VLAN lists decide which VLANs can cross a trunk.
  • Native VLAN mismatch can create confusing symptoms.

TExam Day Tips

  • Use show vlan brief to verify access VLANs.
  • Use show interfaces trunk to verify trunk state and allowed VLANs.
  • Do not treat every same-VLAN issue as a routing problem.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Access ports place end devices into a single VLAN.

What is the correct answer to this question?

The correct answer is: Move finance systems to a separate VLAN or subnet and allow only required traffic through filtering rules. — Separating finance systems into their own VLAN or subnet is a practical way to reduce risk without breaking business workflows. It limits who can talk to the finance devices and allows the organization to apply specific firewall or access control list rules for the printer and accounting application. This is a common and effective way to reduce lateral movement and protect sensitive business systems in a small office. Why others are wrong: A flat network keeps all internal devices equally reachable. Moving the printer is not a security control for traffic isolation. Screen locking helps if a user walks away, but it does not restrict network communications between departments.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.