GSEC Defensible Network Architecture Practice Question
A financial firm is architecting a new cardholder data environment (CDE) that must comply with PCI DSS segmentation requirements. The security team proposes using a single internal VLAN with host-based firewalls on each server to isolate CDE systems from corporate desktops. The auditor rejects this design. Which approach BEST meets the requirement for defensible network segmentation?
⚠ Common exam trap
The trap here is assuming that host-based firewalls or 802.1X authentication can replace network segmentation, when they only protect individual hosts and do not create an auditable isolation boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place CDE systems in a dedicated VLAN and enforce inter-VLAN access control with a stateful firewall that permits only required flows from corporate networks.
A dedicated VLAN combined with a stateful firewall creates a clear enforcement boundary where only explicitly permitted flows can enter the CDE. This design provides the isolation, logging, and policy control that PCI DSS auditors expect. Host-based controls alone cannot substitute for network segmentation because they do not prevent lateral movement across the flat network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place CDE systems in a dedicated VLAN and enforce inter-VLAN access control with a stateful firewall that permits only required flows from corporate networks.
Why this is correct
This isolates the CDE at Layer 2 and enforces a policy enforcement point at Layer 3/4, which is the standard defensible segmentation for PCI DSS. A stateful firewall provides explicit allow rules, logging, and the ability to prove that no unauthorized traffic can reach cardholder systems from corporate desktops.
- ✗
Keep all systems in one VLAN but require 802.1X authentication for every desktop before it can send traffic to CDE servers.
Why it's wrong here
802.1X authenticates devices at the port level but does not prevent an authenticated corporate desktop from reaching the CDE. Once on the same VLAN, the desktop can still initiate connections to cardholder servers. This fails to create the required segmentation boundary and does not satisfy the auditor's demand for isolation.
- ✗
Implement private VLANs (PVLANs) on the access switches so that CDE servers are in an isolated secondary VLAN and corporate desktops are in a community VLAN.
Why it's wrong here
PVLANs restrict Layer 2 communication within a single VLAN, but they do not provide stateful inspection or the ability to allow specific application flows. Placing CDE servers and desktops in different PVLAN types still leaves them in the same broadcast domain and does not scale to the required policy control.
- ✗
Deploy host-based firewalls on each CDE server and configure them to allow only connections from the corporate desktop subnet.
Why it's wrong here
Host-based firewalls protect the server but do not isolate the CDE as a network segment. Corporate desktops remain on the same VLAN, so any compromised desktop can attempt connections to other CDE systems that may have weaker host rules. This approach lacks a network-level enforcement point and is difficult to audit consistently.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.