Courseiva

GSEC Defensible Network Architecture Practice Question

A security architect must ensure that hosts on a guest wireless network cannot reach any internal RFC 1918 subnets, while still allowing guests to reach the internet and a captive portal hosted internally for authentication. The design uses a wireless controller that tunnels guest traffic to a dedicated guest anchor. Which approach best enforces the requirement?

⚠ Common exam trap

Many exam-takers confuse wireless client isolation, which only separates guests from each other, with filtering that blocks guest access to wired internal subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign guests addresses from an isolated guest subnet and apply an ACL on the guest anchor that denies traffic to all internal RFC 1918 ranges while permitting the captive portal host and internet-bound traffic.

Guest traffic tunneled to a dedicated anchor can be filtered where it enters the network, and an ACL that denies RFC 1918 destinations while permitting the captive portal and internet traffic enforces exactly the stated policy. Client isolation, core-level blanket drops, and route publication either fail to block internal access or break required services. The anchor is the correct enforcement point because it sees all guest traffic before it reaches internal resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign guests addresses from an isolated guest subnet and apply an ACL on the guest anchor that denies traffic to all internal RFC 1918 ranges while permitting the captive portal host and internet-bound traffic.

    Why this is correct

    An isolated guest subnet with an ACL that denies RFC 1918 destinations enforces the no-internal-access requirement at the point where guest traffic is anchored. Explicitly permitting the captive portal host and internet destinations preserves the required services, and the deny rule prevents guests from reaching internal subnets even if they discover their addresses. This is the standard guest-anchor enforcement model.

  • ✗

    Assign guests addresses from an isolated guest subnet and publish a route to the internal network, relying on the internal firewalls' implicit deny to block guest access.

    Why it's wrong here

    Publishing a route makes the internal network reachable from the guest subnet and depends on every internal firewall having a correctly ordered deny policy, which is fragile and may not cover all paths. The requirement calls for enforcement at the guest boundary, not reliance on downstream devices. Advertising internal routes to guests also leaks topology information useful for reconnaissance.

  • ✗

    Assign guests addresses from an isolated guest subnet and configure the internal core switches to drop all traffic sourced from that subnet.

    Why it's wrong here

    Dropping all traffic from the guest subnet at the core would also block internet-bound traffic that transits the core, breaking guest connectivity, and the captive portal would become unreachable. Enforcement belongs at the guest anchor where the policy can distinguish permitted destinations from denied internal ranges, not as a blanket drop that ignores the required exceptions.

  • ✗

    Assign guests addresses from the internal corporate DHCP scope and rely on the wireless controller's client isolation feature to prevent guests from reaching internal hosts.

    Why it's wrong here

    Client isolation blocks guest-to-guest traffic on the same wireless network, not guest-to-wired-internal traffic. Placing guests in the corporate scope also means their addresses are routable to internal subnets, so a guest could reach internal hosts unless additional filtering exists. The requirement demands explicit denial of internal RFC 1918 destinations, which this design does not provide.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.