Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)

⚠ Common exam trap

The trap here is selecting monitoring or performance improvements, which detect or speed up traffic, instead of the two controls that actually partition the network and restrict permitted paths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying the principle of least privilege to internal firewall rule sets and access control lists

Containment requires both breaking the flat network into isolated zones and restricting what traffic may cross between them. VLANs with firewall-enforced inter-VLAN rules provide the zones, while least-privilege ACLs and rule sets ensure that any permitted crossing is minimal, together limiting how far a single compromised workstation can spread.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploying a signature-based intrusion detection sensor on the core switch

    Why it's wrong here

    An IDS sensor can alert on known malicious patterns crossing the core, but it does not stop traffic or reduce the reachable surface of an infected host. Detection alone would not have contained the malware spread, since the flat network still permits any host to contact any other host.

  • ✓

    Applying the principle of least privilege to internal firewall rule sets and access control lists

    Why this is correct

    Restricting internal rules and ACLs so each zone can reach only the services it genuinely needs shrinks the paths available for lateral movement. Combined with segmentation, least privilege ensures that even permitted connections are narrowly scoped, so a single compromised workstation cannot pivot broadly across departments.

  • ✗

    Increasing the bandwidth of the internal network backbone between departments

    Why it's wrong here

    Additional bandwidth improves performance and reduces congestion, but it does nothing to constrain where an attacker can move after compromising a host. The flat trust model that allowed the spread would remain unchanged, so this measure does not support containment of the incident.

  • ✓

    Implementing virtual LANs with inter-VLAN filtering by a firewall

    Why this is correct

    Segmenting the flat network into VLANs and forcing inter-VLAN traffic through a firewall with explicit rules limits how far a compromised host can reach. Even if malware runs on one workstation, it cannot freely contact unrelated departments unless a rule permits it, which directly addresses the lateral movement observed in the incident.

  • ✗

    Enabling dynamic host configuration protocol snooping on all access switches

    Why it's wrong here

    DHCP snooping blocks rogue DHCP servers by validating server responses against trusted ports, which helps prevent address misconfiguration and some man-in-the-middle attacks. It is a useful hardening step but does not partition the network or limit lateral movement between departments, so it does not meet the containment objective.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.