GSEC Defensible Network Architecture Practice Question
A security architect is designing a defensible network architecture for a new campus. The architect must implement controls that limit the spread of malware from an infected endpoint to other endpoints on the same VLAN. Which TWO actions should be included in the design? (Choose two.)
⚠ Common exam trap
The trap here is selecting integrity or detection controls like DHCP snooping or honeypots when the requirement is specifically to prevent endpoint-to-endpoint spread through network segmentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement 802.1X with dynamic VLAN assignment so endpoints are placed into role-based segments based on identity and posture.
Limiting malware spread on a campus network requires segmenting endpoints at Layer 2. 802.1X with dynamic VLAN assignment places devices into role-based segments, and private VLANs prevent direct host-to-host communication within a VLAN. Together they reduce the blast radius of an infection. Honeypots, DHCP snooping with IP Source Guard, and host-based IPS improve detection or integrity but do not provide the network segmentation needed to contain lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a host-based intrusion prevention system (HIPS) on every endpoint to block malicious traffic at the source.
Why it's wrong here
A HIPS can block malicious activity on an endpoint, but it is a host-level control and does not segment the network. If the HIPS is bypassed, disabled, or misses a threat, the endpoint can still communicate with peers on the same VLAN. The requirement is to limit spread across the network, which calls for network segmentation controls rather than relying solely on endpoint agents.
- ✓
Implement 802.1X with dynamic VLAN assignment so endpoints are placed into role-based segments based on identity and posture.
Why this is correct
802.1X with dynamic VLAN assignment groups endpoints by role, such as employee, contractor, or guest, and can place unpatched devices into a remediation VLAN. This limits lateral spread because an infected endpoint in one role segment cannot directly reach endpoints in another segment. It is a foundational control for defensible network architecture and directly addresses same-VLAN spread by making VLANs smaller and identity-driven.
- ✗
Deploy a honeypot on each VLAN to detect and automatically blackhole infected endpoints.
Why it's wrong here
A honeypot can detect scanning or exploitation attempts, but it does not automatically blackhole infected endpoints and is not a segmentation control. It provides visibility, not containment. Placing one on every VLAN is also operationally heavy and does not prevent an infected host from reaching its peers. This option overstates the honeypot's role in limiting malware spread.
- ✗
Configure DHCP snooping and IP Source Guard on all access ports to validate endpoint IP and MAC bindings.
Why it's wrong here
DHCP snooping and IP Source Guard prevent IP spoofing and rogue DHCP servers, which are important integrity controls. However, they do not stop an infected endpoint from communicating with other endpoints using its legitimate IP address. Malware can still spread laterally over allowed protocols. These controls harden Layer 2 but do not provide the segmentation needed to contain an infection.
- ✓
Enable private VLANs on access switches to isolate endpoints within the same VLAN from one another while allowing them to reach the default gateway.
Why this is correct
Private VLANs prevent hosts on the same VLAN from communicating directly with each other; they can only reach the promiscuous port, usually the router or firewall. This blocks worm-like lateral movement between endpoints even if they share an IP subnet. It is an effective Layer 2 control for limiting malware spread within a broadcast domain and complements identity-based segmentation.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.