Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?

⚠ Common exam trap

The trap here is assuming that a separate SSID, or strong wireless encryption on that SSID, automatically isolates guest traffic from the internal network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets

Guest isolation requires a logical network boundary, which is achieved by assigning the guest SSID to a dedicated VLAN and enforcing firewall rules that deny access to internal subnets. Wireless encryption, captive portals, and channel selection do not create that boundary. Without the VLAN and firewall policy, guest devices may reach corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets

    Why this is correct

    Placing guest traffic on a dedicated VLAN and applying firewall rules that deny access to internal subnets enforces isolation at the network layer. Even if a guest device is compromised or misconfigured, it cannot route to corporate resources because the policy explicitly blocks that traffic, satisfying the stated requirement.

  • ✗

    Configure the guest SSID to use a captive portal for user registration

    Why it's wrong here

    A captive portal collects information or enforces terms before granting internet access, but it is an authentication and consent mechanism, not a network isolation control. After the portal is satisfied, the guest device still needs a separate VLAN and firewall policy to be prevented from reaching internal corporate resources.

  • ✗

    Enable WPA3-Personal on the guest SSID with a strong pre-shared key

    Why it's wrong here

    WPA3-Personal encrypts the wireless link and protects the pre-shared key exchange, but it does not separate guest traffic from internal networks. Once a guest authenticates, that device is on the same logical network as other users of that SSID, so it may still reach internal resources if no VLAN or firewall boundary exists.

  • ✗

    Set the guest SSID to broadcast on a different wireless channel than the corporate SSID

    Why it's wrong here

    Channel selection affects radio interference and performance, not logical network reachability. Two SSIDs on different channels can still bridge into the same VLAN and internal subnets, so this setting does nothing to prevent guest devices from accessing corporate resources.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.