Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)

⚠ Common exam trap

The trap here is equating endpoint hardening or data-at-rest protection with network reach limitation, when only segmentation and host-based filtering actually restrict where a compromised system can connect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a host-based firewall on each POS system with rules that allow only the payment application and management agent.

A dedicated POS VLAN with a restrictive ACL and a host-based firewall on each terminal both enforce least privilege on network reachability. The VLAN and ACL stop lateral movement at the network layer, while the host firewall restricts the endpoint's own traffic to only necessary services. Antivirus, password complexity, and full-disk encryption improve other areas but do not limit what a compromised POS system can reach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require a complex password on the local administrator account of each POS system.

    Why it's wrong here

    A strong local administrator password makes credential guessing harder, but it does not constrain network traffic from a compromised POS system. Once an attacker has code execution, they can often use the current session or extract credentials. This is a host hardening measure, not a network reach-limiting control, so it does not directly reduce what the terminal can reach.

  • ✓

    Deploy a host-based firewall on each POS system with rules that allow only the payment application and management agent.

    Why this is correct

    A host-based firewall on the POS system enforces least privilege at the endpoint by permitting only required outbound and inbound flows for the payment application and management agent. Even if the terminal is compromised, other network paths are blocked. This directly limits what the system can reach, complementing network segmentation.

  • ✗

    Enable full-disk encryption on the POS system drives to protect data at rest.

    Why it's wrong here

    Full-disk encryption protects data if a drive is physically removed or the device is lost, but it does not affect network reachability from a running, compromised POS system. An attacker with code execution can read decrypted data and still move laterally. This control addresses data-at-rest confidentiality rather than limiting network access.

  • ✗

    Install an antivirus agent on each POS system and schedule a full scan every night.

    Why it's wrong here

    Antivirus scans can detect known malware on the endpoint, but they do not limit what the POS system can reach over the network. A compromised or zero-day-infected terminal could still communicate laterally with corporate servers. This control addresses endpoint malware detection, not network reachability, so it does not meet the stated goal.

  • ✓

    Place POS systems on a dedicated VLAN with an ACL that allows only traffic to the payment processor and a management server.

    Why this is correct

    A dedicated POS VLAN with a restrictive ACL limits east-west movement, so a compromised terminal cannot scan or reach unrelated corporate systems. Only the payment processor and management server remain reachable, which directly shrinks the attack surface. This is a segmentation control that enforces least privilege at the network layer.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.