GSEC Network Security Devices Practice Question
A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?
⚠ Common exam trap
The trap here is thinking that different IP subnets on the same VLAN provide security separation, when Layer 2 adjacency still allows direct host-to-host traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate VLANs for guest and internal users, and apply an ACL on the router interface that blocks traffic from the guest VLAN to the internal VLAN.
Segmenting guest and internal users into separate VLANs creates distinct Layer 2 domains, and because traffic between them must be routed, an ACL on the router interface can block guest-to-internal access. This is the most direct and reliable way to enforce the requirement with the described equipment. Same-VLAN addressing, Layer 2 hardening features, and private VLANs either do not enforce the policy or are more complex and less certain for this specific goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable private VLANs on the switch so that guest ports can communicate only with the router port.
Why it's wrong here
Private VLANs can isolate ports within a VLAN and force traffic through a promiscuous port, which is useful for some segmentation designs. However, if guest and internal users remain in the same primary VLAN, the isolation rules may not cleanly separate them from internal file servers, and configuration complexity is high. The more direct and commonly supported approach is separate VLANs plus a router ACL, which unambiguously blocks guest-to-internal traffic.
- ✗
Configure port security on all switch ports to limit the number of MAC addresses, and enable DHCP snooping on the guest VLAN.
Why it's wrong here
Port security and DHCP snooping protect against MAC flooding and rogue DHCP servers, but they do not prevent a guest host from sending IP traffic to an internal file server on the same Layer 2 network. These are Layer 2 hardening features, not inter-segment access controls. The requirement is to stop guest users from reaching internal servers, which needs logical separation and a routed policy enforcement point, neither of which this option provides.
- ✗
Place guest users on the same VLAN as internal users but assign them static IP addresses in a different subnet range.
Why it's wrong here
Using different IP subnets on the same VLAN does not create a security boundary; hosts on the same Layer 2 segment can still communicate directly via ARP and MAC addressing, bypassing any router ACL. Without VLAN separation, the router is not in the path for local traffic, so an ACL cannot enforce segmentation. This approach gives a false sense of separation and does not prevent guest users from reaching internal file servers.
- ✓
Create separate VLANs for guest and internal users, and apply an ACL on the router interface that blocks traffic from the guest VLAN to the internal VLAN.
Why this is correct
VLANs logically separate the guest and internal broadcast domains, and an ACL on the router interface enforces policy between them. Because inter-VLAN traffic must be routed, the router is the correct enforcement point. This combination directly prevents guest users from reaching internal file servers while still allowing both groups to reach the internet through controlled paths. It is the standard and effective way to segment a flat network with existing Layer 2 and Layer 3 equipment.
Visual reference
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.