Courseiva
Network Security Devices →mediumMultiple Choice

GSEC Network Security Devices Practice Question

A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?

⚠ Common exam trap

The trap here is assuming that any inline device automatically fails open, when in fact fail-to-wire depends on a dedicated hardware bypass segment rather than software configuration alone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a Layer 2 bridge running in inline mode with a hardware bypass fail-to-wire segment.

Transparent inline bridging with a hardware bypass segment keeps the appliance invisible at Layer 3 while still allowing it to enforce policy on traffic crossing between VLANs. The fail-to-wire path guarantees that clinical connectivity survives a power loss, which is the decisive requirement distinguishing this from passive monitoring or routed insertion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the appliance as a routed hop between the two VLANs with a static route on each side.

    Why it's wrong here

    Inserting a routed hop changes the Layer 3 topology and requires gateway or route changes on the clinical and guest VLANs, violating the requirement to avoid IP addressing changes. A routed deployment also creates a single point of failure unless additional redundancy is configured, and it is not transparent to the existing network design.

  • ✗

    Deploy a TAP aggregator that mirrors both VLANs to the appliance and enable fail-open on the NIC.

    Why it's wrong here

    A network TAP copies traffic passively; it does not place the appliance in the forwarding path, so no prevention between the VLANs is possible. NIC-level fail-open only affects the appliance's own interface state and cannot restore a path that was never inline, leaving the clinical-to-guest traffic uninspected and unblocked.

  • ✓

    Deploy a Layer 2 bridge running in inline mode with a hardware bypass fail-to-wire segment.

    Why this is correct

    An inline Layer 2 bridge inspects traffic between the two VLANs while remaining transparent to IP addressing, and a hardware bypass fail-to-wire segment physically shunts packets around the appliance if it loses power, preserving connectivity for clinical systems. This directly satisfies both the inspection and the survivability requirements without renumbering hosts or altering routing.

  • ✗

    Deploy a SPAN port on the core switch and attach the appliance in passive monitor-only mode.

    Why it's wrong here

    A SPAN-based passive deployment copies frames to the monitoring interface but has no ability to block malicious traffic, so it cannot enforce policy between the clinical and guest VLANs. It also fails the availability requirement differently: while the network survives an appliance failure, the appliance provides no inline protection at all, which is not what the scenario asks for.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.