Courseiva

GSEC Defensible Network Architecture Practice Question

An enterprise network design utilizes an out-of-band management network for all core routers, firewalls, and switches. The management network is physically separated from the production data plane and uses dedicated management switches. What is the primary security advantage of this defensible architecture?

⚠ Common exam trap

Test-takers frequently assume out-of-band networks are designed to speed up administrative throughput or encrypt regular production workloads, missing their core security purpose of stopping lateral attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents compromised production workloads from launching lateral attacks against device management planes.

An out-of-band management network isolates administrative traffic from production data flows, ensuring that an operational disruption or compromise of the data plane does not lock administrators out of their infrastructure devices. This separation prevents lateral movement from compromised user workstations directly into device management interfaces, protecting critical administrative access paths.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It completely eliminates the requirement to encrypt administrative SSH and HTTPS sessions across the network core.

    Why it's wrong here

    Physical separation of management traffic does not replace the necessity of encryption. Administrative sessions must still be encrypted using secure protocols like SSH and HTTPS to protect credentials and configuration data from internal packet capture tools.

  • ✓

    It prevents compromised production workloads from launching lateral attacks against device management planes.

    Why this is correct

    Physical separation ensures that even if an attacker completely compromises the production data plane, they cannot reach the management plane interfaces because there is no direct network path between the two distinct environments, protecting critical device controls.

  • ✗

    It automatically accelerates routing convergence times across all enterprise boundary routers by removing administrative overhead.

    Why it's wrong here

    Physical separation of management traffic removes a production-plane attack path, limiting lateral movement from compromised hosts to network devices. Routing convergence speed is governed by protocol timers and topology, not management-plane isolation. Convergence tuning is a design goal, not a security advantage.

  • ✗

    It allows network operators to utilize unauthenticated cleartext telnet connections without risking confidentiality breaches.

    Why it's wrong here

    Physical separation protects the management plane from production traffic, but telnet still transmits credentials and commands in cleartext across the management segment; anyone with access there captures them. Telnet is tempting for legacy out-of-band console access where a terminal server offers no encryption, but SSH provides the same reach securely.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.