ISC2 CC Network Security Practice Question
A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?
⚠ Common exam trap
The trap is conflating Layer 3 subnetting with Layer 2 segmentation — CC candidates often pick 'subnetting' because it sounds like separation, but only VLANs isolate traffic on the same physical switch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VLAN
A VLAN (Virtual LAN, IEEE 802.1Q) logically segments a single physical switch into multiple isolated broadcast domains, allowing the Accounting and HR departments to share hardware while remaining logically separated at Layer 2. This is the standard technology for departmental segmentation on a common switch. Subnetting operates at Layer 3 and does not by itself isolate traffic on the same switch without VLANs or ACLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subnetting
Why it's wrong here
Subnetting operates at Layer 3, partitioning IP address space into separate broadcast domains, but a single physical switch still carries all VLAN traffic unless logically segmented at Layer 2. It would be correct when dividing an existing IP network into smaller routed subnets, not for isolating departments on shared switch hardware.
- ✗
DMZ
Why it's wrong here
A DMZ is a perimeter network segment exposing public-facing services to untrusted traffic, not an internal segmentation mechanism between departments on one switch. It would be the right choice when hosting externally accessible servers, such as web or mail gateways, that must be shielded from the internal LAN.
- ✓
VLAN
Why this is correct
A VLAN applies 802.1Q tagging to logically segment switch ports into separate broadcast domains, so Accounting and HR traffic stays isolated despite sharing one physical switch. This directly satisfies the stem's constraint of logical separation on common hardware, without requiring additional switches or physical rewiring.
- ✗
Honeypot
Why it's wrong here
A honeypot is a decoy system that lures and observes attackers; it cannot segment traffic or enforce separation between departments. VLANs logically partition one physical switch into isolated broadcast domains, which is what the scenario requires. Honeypots are correct for threat detection and research, not departmental isolation.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.