ISC2 CC Network Security Practice Question
A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?
⚠ Common exam trap
The trap here is assuming that a separate SSID, or strong wireless encryption on that SSID, automatically isolates guest traffic from the internal network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets
Guest isolation requires a logical network boundary, which is achieved by assigning the guest SSID to a dedicated VLAN and enforcing firewall rules that deny access to internal subnets. Wireless encryption, captive portals, and channel selection do not create that boundary. Without the VLAN and firewall policy, guest devices may reach corporate resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets
Why this is correct
Placing guest traffic on a dedicated VLAN and applying firewall rules that deny access to internal subnets enforces isolation at the network layer. Even if a guest device is compromised or misconfigured, it cannot route to corporate resources because the policy explicitly blocks that traffic, satisfying the stated requirement.
- ✗
Configure the guest SSID to use a captive portal for user registration
Why it's wrong here
A captive portal collects information or enforces terms before granting internet access, but it is an authentication and consent mechanism, not a network isolation control. After the portal is satisfied, the guest device still needs a separate VLAN and firewall policy to be prevented from reaching internal corporate resources.
- ✗
Enable WPA3-Personal on the guest SSID with a strong pre-shared key
Why it's wrong here
WPA3-Personal encrypts the wireless link and protects the pre-shared key exchange, but it does not separate guest traffic from internal networks. Once a guest authenticates, that device is on the same logical network as other users of that SSID, so it may still reach internal resources if no VLAN or firewall boundary exists.
- ✗
Set the guest SSID to broadcast on a different wireless channel than the corporate SSID
Why it's wrong here
Channel selection affects radio interference and performance, not logical network reachability. Two SSIDs on different channels can still bridge into the same VLAN and internal subnets, so this setting does nothing to prevent guest devices from accessing corporate resources.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Isolation
Isolation is the process of separating a compromised or suspicious system from a network to prevent the spread of malware or unauthorized access.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.