Question 219 of 1,013
PCI DSS Network Segmentation: Isolating the Cardholder Data Environment
A security architect is redesigning the network for a payment card processing environment. The goal is to create a cardholder data environment (CDE) that is isolated from the rest of the corporate network to reduce PCI DSS scope. The CDE will contain only the payment application servers and the database storing credit card numbers. The architect must allow authorized administrators in the corporate network to perform updates and monitoring on the CDE servers. Which of the following network architecture designs provides the strongest isolation while still meeting the requirement for authorized administrative access?
Quick Answer
The correct choice is to deploy a dedicated firewall that connects the corporate network to an isolated CDE segment, with rules allowing only SSH and RDP from a specific jump box. This design achieves PCI DSS network segmentation by creating a true isolation boundary around the cardholder data environment, which is essential for reducing compliance scope. The dedicated firewall enforces strict least-privilege access, ensuring that only authorized administrators can reach the CDE through a single controlled entry point, while all other corporate traffic is denied. On the Security+ SY0-701 exam, this scenario tests your understanding of network segmentation and access control as part of domain 3.0 (Security Architecture). A common trap is choosing a VLAN alone, which lacks the firewall’s explicit rule enforcement and can be bridged. Remember the mnemonic “Jump to Isolate” — a jump box plus a dedicated firewall is the gold standard for CDE isolation.
⚠ Common exam trap
Candidates often think VLANs with ACLs (Option C) provide sufficient isolation, but PCI DSS requires a clear network segmentation boundary enforced by a firewall, not just Layer 3 ACLs or host-based controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a dedicated firewall that connects the corporate network to an isolated CDE segment. Configure firewall rules to allow only SSH and RDP from a specific jump box in the corporate network to the CDE servers, and deny all other inbound traffic from the corporate network.
It uses a dedicated firewall to create a true network isolation boundary between the corporate network and the CDE, which is a core PCI DSS requirement for reducing scope. By allowing only SSH and RDP from a specific jump box, it enforces strict least-privilege administrative access while preventing any direct or uncontrolled traffic from the corporate network. This design ensures that the CDE is a separate, protected segment with a single controlled entry point, meeting both isolation and authorized access needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the CDE servers on a separate subnet within the same VLAN as the corporate network, and rely on host-based firewalls on each server to deny all traffic except from specific administrative IP addresses.
Why it's wrong here
This design uses a shared VLAN and relies solely on host-based firewalls. A shared VLAN means the CDE servers are on the same Layer 2 broadcast domain as the corporate network; a network misconfiguration or compromised device could allow lateral traffic to bypass host firewalls. Host-based firewalls are less robust than network-level isolation, making this option insecure.
When this WOULD be correct
This option would be correct in a scenario where the organization has a flat network with limited budget, and the requirement is to quickly segregate a low-risk system (e.g., a test environment) using existing infrastructure, with host-based firewalls as a compensating control. The question would emphasize cost-effectiveness and minimal hardware changes.
- ✓
Deploy a dedicated firewall that connects the corporate network to an isolated CDE segment. Configure firewall rules to allow only SSH and RDP from a specific jump box in the corporate network to the CDE servers, and deny all other inbound traffic from the corporate network.
Why this is correct
A dedicated firewall provides strong network-level segmentation between the corporate network and the CDE. Using a jump box (bastion host) as the sole admin entry point limits exposure and allows for centralized logging and auditing. This design meets both isolation and authorized access requirements.
- ✗
Place the CDE servers on a separate VLAN with a Layer 3 switch that uses ACLs to allow only ICMP traffic from the corporate network to the CDE for monitoring, and require administrators to physically connect to the CDE network via a dedicated console server.
Why it's wrong here
While this uses VLAN separation, the ACL only permits ICMP, which is insufficient for administration (no SSH/RDP). Requiring physical console access is impractical for routine updates and monitoring, and it does not support remote management. This design fails to meet the business requirement.
When this WOULD be correct
This option would be correct in a scenario where the requirement is to allow only passive monitoring (e.g., ping checks) from the corporate network, and all administrative access must be performed via out-of-band management (e.g., dedicated console server) for high-security environments where no remote network access to the CDE is permitted.
- ✗
Connect the CDE servers directly to the internet through a web application firewall (WAF), and require all management access to occur through a cloud-based VPN with two-factor authentication.
Why it's wrong here
Directly connecting the CDE to the internet exposes it to external threats, even with a WAF. CDE servers should never be directly internet-facing. While a VPN adds encryption, the design violates the principle of network isolation required by PCI DSS, significantly increasing the attack surface.
When this WOULD be correct
This design could be correct for a public-facing web application that does not handle cardholder data, where the goal is to protect against web application attacks while allowing external access and management via a secure VPN.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Deploy a dedicated firewall that connects the corporate network to an isolated CDE segment. Configure firewall rules to allow only SSH and RDP from a specific jump box in the corporate network to the CDE servers, and deny all other inbound traffic from the corporate network.Correct answer▾
Why this is correct
A dedicated firewall provides strong network-level segmentation between the corporate network and the CDE. Using a jump box (bastion host) as the sole admin entry point limits exposure and allows for centralized logging and auditing. This design meets both isolation and authorized access requirements.
✗Place the CDE servers on a separate subnet within the same VLAN as the corporate network, and rely on host-based firewalls on each server to deny all traffic except from specific administrative IP addresses.Wrong answer — click to see why▾
Why this is wrong here
Placing CDE servers on a separate subnet within the same VLAN as the corporate network does not provide true isolation, as VLANs share the same broadcast domain and Layer 2 boundaries. Host-based firewalls are less secure than a dedicated network firewall and can be more easily misconfigured or bypassed, failing to meet PCI DSS requirements for strong segmentation.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the organization has a flat network with limited budget, and the requirement is to quickly segregate a low-risk system (e.g., a test environment) using existing infrastructure, with host-based firewalls as a compensating control. The question would emphasize cost-effectiveness and minimal hardware changes.
Why candidates choose this
Candidates may think that a separate subnet and host-based firewalls provide sufficient isolation, underestimating the importance of network-level segmentation and dedicated firewalls in PCI DSS. They might also overestimate the security of VLANs and host-based controls.
✗Place the CDE servers on a separate VLAN with a Layer 3 switch that uses ACLs to allow only ICMP traffic from the corporate network to the CDE for monitoring, and require administrators to physically connect to the CDE network via a dedicated console server.Wrong answer — click to see why▾
Why this is wrong here
Option C is wrong because allowing ICMP traffic from the corporate network to the CDE creates a potential attack vector (e.g., ICMP tunneling) and does not provide the required administrative access for updates and monitoring via SSH/RDP. Additionally, requiring physical connection via a console server is impractical for routine remote administration.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the requirement is to allow only passive monitoring (e.g., ping checks) from the corporate network, and all administrative access must be performed via out-of-band management (e.g., dedicated console server) for high-security environments where no remote network access to the CDE is permitted.
Why candidates choose this
Candidates may find this option tempting because it uses VLAN segmentation and ACLs, which are common security controls, and the idea of physical console access seems highly secure. However, they overlook the need for remote administrative access and the risks of allowing ICMP traffic.
✗Connect the CDE servers directly to the internet through a web application firewall (WAF), and require all management access to occur through a cloud-based VPN with two-factor authentication.Wrong answer — click to see why▾
Why this is wrong here
Connecting CDE servers directly to the internet, even with a WAF, exposes them to external threats and violates PCI DSS requirements for network segmentation and isolation of the CDE from untrusted networks.
★ When this WOULD be the correct answer
This design could be correct for a public-facing web application that does not handle cardholder data, where the goal is to protect against web application attacks while allowing external access and management via a secure VPN.
Why candidates choose this
Candidates may be attracted to the use of a WAF and two-factor VPN as strong security controls, overlooking the fundamental requirement to isolate the CDE from the internet to reduce PCI DSS scope.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security architect at a retail company is deploying a new e-commerce platform that processes credit card payments. The architect needs to minimize the scope of the PCI DSS assessment. The platform consists of a web server, an application server, and a database server. The cardholder data (credit card numbers) will be processed and stored only on the database server. Which of the following network architecture designs would best reduce the PCI DSS scope?
medium- A.Place all servers in the same VLAN and apply a host-based firewall on the database server.
- ✓ B.Place the database server in a separate, isolated network segment with a dedicated firewall that blocks all traffic except from the application server on the required port.
- C.Encrypt all data in transit using TLS and at rest using AES-256.
- D.Implement network intrusion detection systems on all network segments.
Why B: Isolating the database server in a separate network segment with a dedicated firewall that restricts traffic to only the application server on the required port creates a clear network segmentation boundary. This segmentation limits the cardholder data environment (CDE) to just the database server, thereby minimizing the scope of the PCI DSS assessment by excluding the web and application servers from the CDE.
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.