Courseiva
Network Security Devices →easyMultiple Choice

GSEC Network Security Devices Practice Question

A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?

⚠ Common exam trap

The trap here is thinking that different IP subnets on the same VLAN provide security separation, when Layer 2 adjacency still allows direct host-to-host traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate VLANs for guest and internal users, and apply an ACL on the router interface that blocks traffic from the guest VLAN to the internal VLAN.

Segmenting guest and internal users into separate VLANs creates distinct Layer 2 domains, and because traffic between them must be routed, an ACL on the router interface can block guest-to-internal access. This is the most direct and reliable way to enforce the requirement with the described equipment. Same-VLAN addressing, Layer 2 hardening features, and private VLANs either do not enforce the policy or are more complex and less certain for this specific goal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable private VLANs on the switch so that guest ports can communicate only with the router port.

    Why it's wrong here

    Private VLANs can isolate ports within a VLAN and force traffic through a promiscuous port, which is useful for some segmentation designs. However, if guest and internal users remain in the same primary VLAN, the isolation rules may not cleanly separate them from internal file servers, and configuration complexity is high. The more direct and commonly supported approach is separate VLANs plus a router ACL, which unambiguously blocks guest-to-internal traffic.

  • ✗

    Configure port security on all switch ports to limit the number of MAC addresses, and enable DHCP snooping on the guest VLAN.

    Why it's wrong here

    Port security and DHCP snooping protect against MAC flooding and rogue DHCP servers, but they do not prevent a guest host from sending IP traffic to an internal file server on the same Layer 2 network. These are Layer 2 hardening features, not inter-segment access controls. The requirement is to stop guest users from reaching internal servers, which needs logical separation and a routed policy enforcement point, neither of which this option provides.

  • ✗

    Place guest users on the same VLAN as internal users but assign them static IP addresses in a different subnet range.

    Why it's wrong here

    Using different IP subnets on the same VLAN does not create a security boundary; hosts on the same Layer 2 segment can still communicate directly via ARP and MAC addressing, bypassing any router ACL. Without VLAN separation, the router is not in the path for local traffic, so an ACL cannot enforce segmentation. This approach gives a false sense of separation and does not prevent guest users from reaching internal file servers.

  • ✓

    Create separate VLANs for guest and internal users, and apply an ACL on the router interface that blocks traffic from the guest VLAN to the internal VLAN.

    Why this is correct

    VLANs logically separate the guest and internal broadcast domains, and an ACL on the router interface enforces policy between them. Because inter-VLAN traffic must be routed, the router is the correct enforcement point. This combination directly prevents guest users from reaching internal file servers while still allowing both groups to reach the internet through controlled paths. It is the standard and effective way to segment a flat network with existing Layer 2 and Layer 3 equipment.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.