CISA Protection of Information Assets Practice Question
Which of the following is the PRIMARY reason for implementing network segmentation?
⚠ Common exam trap
CISA often tests the distinction between primary and secondary benefits — candidates pick 'improve network performance' because segmentation can reduce broadcast traffic, but the PRIMARY reason is security containment and limiting lateral movement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To contain security breaches and limit lateral movement.
The primary reason for network segmentation is to contain security breaches and limit lateral movement — by dividing the network into isolated zones, an attacker who compromises one segment cannot freely move to others. This is a foundational defense-in-depth control that reduces the blast radius of a breach and protects critical assets. While segmentation can have secondary benefits, security containment is its primary purpose in modern network design.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To comply with licensing requirements.
Why it's wrong here
Licensing counts users, devices or features, not broadcast domains, so segmentation does not satisfy any licensing obligation. It is tempting because segmentation reduces broadcast scope and enforces policy boundaries, and would be the right control where a scenario requires containing sensitive systems or limiting lateral movement after compromise.
- ✗
To simplify IP address management.
Why it's wrong here
Subnetting eases address administration, but segmentation exists to constrain reachability between zones, not to tidy IP plans. It is tempting because each segment typically receives its own subnet, and would be correct where the requirement is structured addressing or summarisation rather than isolating systems and containing breaches.
- ✓
To contain security breaches and limit lateral movement.
Why this is correct
Segmentation places enforcement points between network zones, so a compromised host cannot freely reach other systems. This directly satisfies the containment constraint: it restricts lateral movement, limiting blast radius and buying incident responders time before the attacker pivots to critical assets.
- ✗
To improve network performance.
Why it's wrong here
Performance gains are incidental; segmentation's primary driver is limiting the blast radius and enforcing trust boundaries between zones. It is tempting because splitting broadcast domains genuinely reduces contention and congestion, and would be the correct answer where the stem asks about throughput or bandwidth optimisation rather than security containment.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.