ISC2 CC Network Security Practice Question
A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)
⚠ Common exam trap
The trap here is selecting monitoring or performance improvements, which detect or speed up traffic, instead of the two controls that actually partition the network and restrict permitted paths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Applying the principle of least privilege to internal firewall rule sets and access control lists
Containment requires both breaking the flat network into isolated zones and restricting what traffic may cross between them. VLANs with firewall-enforced inter-VLAN rules provide the zones, while least-privilege ACLs and rule sets ensure that any permitted crossing is minimal, together limiting how far a single compromised workstation can spread.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying a signature-based intrusion detection sensor on the core switch
Why it's wrong here
An IDS sensor can alert on known malicious patterns crossing the core, but it does not stop traffic or reduce the reachable surface of an infected host. Detection alone would not have contained the malware spread, since the flat network still permits any host to contact any other host.
- ✓
Applying the principle of least privilege to internal firewall rule sets and access control lists
Why this is correct
Restricting internal rules and ACLs so each zone can reach only the services it genuinely needs shrinks the paths available for lateral movement. Combined with segmentation, least privilege ensures that even permitted connections are narrowly scoped, so a single compromised workstation cannot pivot broadly across departments.
- ✗
Increasing the bandwidth of the internal network backbone between departments
Why it's wrong here
Additional bandwidth improves performance and reduces congestion, but it does nothing to constrain where an attacker can move after compromising a host. The flat trust model that allowed the spread would remain unchanged, so this measure does not support containment of the incident.
- ✓
Implementing virtual LANs with inter-VLAN filtering by a firewall
Why this is correct
Segmenting the flat network into VLANs and forcing inter-VLAN traffic through a firewall with explicit rules limits how far a compromised host can reach. Even if malware runs on one workstation, it cannot freely contact unrelated departments unless a rule permits it, which directly addresses the lateral movement observed in the incident.
- ✗
Enabling dynamic host configuration protocol snooping on all access switches
Why it's wrong here
DHCP snooping blocks rogue DHCP servers by validating server responses against trusted ports, which helps prevent address misconfiguration and some man-in-the-middle attacks. It is a useful hardening step but does not partition the network or limit lateral movement between departments, so it does not meet the containment objective.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.