GSEC Defense in Depth Practice Question
A small financial firm has a flat network with no internal segmentation. The security team wants to apply defense in depth to limit the blast radius of a compromised workstation. Which action best aligns with that goal?
⚠ Common exam trap
Many exam-takers confuse access control at the perimeter or authentication layer with internal containment; only segmentation limits what a compromised host can reach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segmenting the network into VLANs based on function and applying ACLs between them
To limit the blast radius of a compromised workstation, the firm needs internal segmentation that restricts lateral movement. VLANs with inter-VLAN ACLs create logical boundaries so that a compromised host cannot freely access other segments. This is a classic defense-in-depth control that adds an internal layer beyond perimeter defenses. Authentication and WAF controls address different threats and do not contain an internal compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementing 802.1X port-based network access control on all switch ports
Why it's wrong here
802.1X controls which devices can connect to the network, but once admitted, a compromised workstation can still reach other hosts on the same flat network. It does not limit lateral movement or reduce the blast radius after compromise. The goal is to contain an already-compromised endpoint, so port-based authentication alone is insufficient.
- ✗
Deploying a web application firewall (WAF) in front of the firm's public website
Why it's wrong here
A WAF protects web applications from external attacks by filtering HTTP traffic, but it does not address internal lateral movement from a compromised workstation. The scenario is about limiting the impact of an internal compromise, not defending a public web service. A WAF operates at the application layer for external-facing services and does not segment internal networks.
- ✗
Enforcing strong password policies and multi-factor authentication for all users
Why it's wrong here
Strong authentication reduces the likelihood of credential compromise, but it does not contain an attacker who already has a foothold on a workstation. Once compromised, the attacker can move laterally regardless of password policies. The scenario asks for limiting blast radius after compromise, which requires network segmentation, not authentication hardening.
- ✓
Segmenting the network into VLANs based on function and applying ACLs between them
Why this is correct
VLAN segmentation with inter-VLAN access control lists restricts traffic between network segments, so a compromised workstation in one VLAN cannot freely reach hosts in other VLANs. This directly limits lateral movement and reduces the blast radius, which is a core defense-in-depth principle. It adds an internal boundary that complements perimeter controls.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.