Courseiva

GSEC Defensible Network Architecture Practice Question

A security architect is designing a defensible network architecture for a new campus. The architect must implement controls that limit the spread of malware from an infected endpoint to other endpoints on the same VLAN. Which TWO actions should be included in the design? (Choose two.)

⚠ Common exam trap

The trap here is selecting integrity or detection controls like DHCP snooping or honeypots when the requirement is specifically to prevent endpoint-to-endpoint spread through network segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement 802.1X with dynamic VLAN assignment so endpoints are placed into role-based segments based on identity and posture.

Limiting malware spread on a campus network requires segmenting endpoints at Layer 2. 802.1X with dynamic VLAN assignment places devices into role-based segments, and private VLANs prevent direct host-to-host communication within a VLAN. Together they reduce the blast radius of an infection. Honeypots, DHCP snooping with IP Source Guard, and host-based IPS improve detection or integrity but do not provide the network segmentation needed to contain lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a host-based intrusion prevention system (HIPS) on every endpoint to block malicious traffic at the source.

    Why it's wrong here

    A HIPS can block malicious activity on an endpoint, but it is a host-level control and does not segment the network. If the HIPS is bypassed, disabled, or misses a threat, the endpoint can still communicate with peers on the same VLAN. The requirement is to limit spread across the network, which calls for network segmentation controls rather than relying solely on endpoint agents.

  • ✓

    Implement 802.1X with dynamic VLAN assignment so endpoints are placed into role-based segments based on identity and posture.

    Why this is correct

    802.1X with dynamic VLAN assignment groups endpoints by role, such as employee, contractor, or guest, and can place unpatched devices into a remediation VLAN. This limits lateral spread because an infected endpoint in one role segment cannot directly reach endpoints in another segment. It is a foundational control for defensible network architecture and directly addresses same-VLAN spread by making VLANs smaller and identity-driven.

  • ✗

    Deploy a honeypot on each VLAN to detect and automatically blackhole infected endpoints.

    Why it's wrong here

    A honeypot can detect scanning or exploitation attempts, but it does not automatically blackhole infected endpoints and is not a segmentation control. It provides visibility, not containment. Placing one on every VLAN is also operationally heavy and does not prevent an infected host from reaching its peers. This option overstates the honeypot's role in limiting malware spread.

  • ✗

    Configure DHCP snooping and IP Source Guard on all access ports to validate endpoint IP and MAC bindings.

    Why it's wrong here

    DHCP snooping and IP Source Guard prevent IP spoofing and rogue DHCP servers, which are important integrity controls. However, they do not stop an infected endpoint from communicating with other endpoints using its legitimate IP address. Malware can still spread laterally over allowed protocols. These controls harden Layer 2 but do not provide the segmentation needed to contain an infection.

  • ✓

    Enable private VLANs on access switches to isolate endpoints within the same VLAN from one another while allowing them to reach the default gateway.

    Why this is correct

    Private VLANs prevent hosts on the same VLAN from communicating directly with each other; they can only reach the promiscuous port, usually the router or firewall. This blocks worm-like lateral movement between endpoints even if they share an IP subnet. It is an effective Layer 2 control for limiting malware spread within a broadcast domain and complements identity-based segmentation.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.