GSEC Defense in Depth Practice Question
A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?
⚠ Common exam trap
Many candidates confuse segmentation enforcement controls with monitoring controls, when the scenario explicitly asks for detection after traffic already crosses a boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install a network intrusion detection system (NIDS) with a span port monitoring traffic between the VLANs.
The architect needs visibility into traffic that crosses the segmentation boundary, which is a detective control function. A network intrusion detection system monitoring a SPAN port sees copies of packets traversing the inter-VLAN link and can alert on malicious patterns. WAFs, 802.1X, and private VLANs either focus on web traffic or enforce preventive access restrictions, none of which detect successful cross-segment intrusions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure private VLANs to prevent hosts within the cardholder data environment from communicating with each other.
Why it's wrong here
Private VLANs restrict east-west traffic inside a single VLAN, adding a preventive segmentation layer. They do not observe or alert on malicious traffic that traverses the boundary between the cardholder and corporate segments. The architect specifically asked for detection of successful cross-segment attacks, and private VLANs provide isolation rather than visibility.
- ✗
Deploy a web application firewall (WAF) in front of the cardholder data environment.
Why it's wrong here
A WAF inspects HTTP and HTTPS application traffic for web-specific attacks such as SQL injection, but it does not monitor general network traffic between VLANs. Malicious traffic using non-web protocols, lateral movement, or command-and-control channels would pass unnoticed. The scenario calls for detecting cross-segment malicious traffic, which is broader than web application protection.
- ✗
Enable 802.1X port-based network access control on all switch ports in both VLANs.
Why it's wrong here
802.1X authenticates devices before granting switch port access, which is a preventive access control. It does not inspect traffic after authentication or detect malicious activity crossing between VLANs. An authenticated but compromised host could still send malicious traffic that 802.1X would never flag, so it does not satisfy the detective requirement.
- ✓
Install a network intrusion detection system (NIDS) with a span port monitoring traffic between the VLANs.
Why this is correct
A NIDS receiving a copy of inter-segment traffic via a SPAN port analyzes packets for known attack signatures and anomalies. If malicious traffic crosses the segmentation boundary, the NIDS raises an alert, providing the detective layer the architect wants. It does not block traffic, which matches the requirement for detection rather than prevention.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.