Courseiva

GSEC Defensible Network Architecture Practice Question

A security engineer is designing a secure enterprise environment and needs to deploy network intrusion detection sensors to monitor east-west traffic moving between virtual machines inside an internal virtualization cluster. Which deployment method ensures the sensors successfully inspect internal segment traffic without introducing a single point of failure for packet forwarding?

⚠ Common exam trap

Candidates often choose inline network security appliances that introduce a single point of failure or latency, forgetting that the question specifically requests monitoring internal east-west traffic without disrupting packet forwarding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuring hypervisor-level distributed virtual switches to mirror east-west traffic to dedicated virtual security monitoring appliances.

Using virtual tap interfaces or distributed software switches configured for port mirroring allows security sensors to receive copies of internal traffic traversing the hypervisor backplane. This approach ensures comprehensive visibility into east-west lateral movement without altering inline packet forwarding paths, maintaining network availability while delivering the necessary telemetry for threat detection engines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Placing a dedicated physical inline bump-in-the-wire network intrusion prevention system between every internal virtual switch uplink.

    Why it's wrong here

    Inserting physical inline appliances between every internal virtual switch uplink creates severe cabling complexity and introduces single points of failure. Any hardware malfunction in the inspection device immediately halts internal east-west traffic across the entire virtualization infrastructure cluster.

  • ✓

    Configuring hypervisor-level distributed virtual switches to mirror east-west traffic to dedicated virtual security monitoring appliances.

    Why this is correct

    Hypervisor-level distributed switching capabilities can securely replicate internal virtual machine traffic patterns and send packet copies to virtualized sensor nodes. This out-of-band monitoring approach guarantees comprehensive visibility into east-west communications without risking packet drop or network downtime.

  • ✗

    Routing all inter-VLAN traffic through a single legacy perimeter firewall using hardware router-on-a-stick configurations.

    Why it's wrong here

    Routing internal east-west traffic through a single perimeter firewall creates an extreme routing bottleneck and fails to inspect intra-VLAN traffic residing on the same subnet. Furthermore, legacy routing configurations cannot adequately scale to handle high-throughput internal virtualization demands.

  • ✗

    Disabling all stateful packet inspection on internal firewalls to allow maximum throughput for east-west virtualization traffic.

    Why it's wrong here

    Disabling stateful packet inspection removes essential security boundaries and visibility into active network sessions. This dangerous configuration leaves internal workloads entirely unprotected against lateral malware propagation and unauthorized administrative access attempts.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.