ISC2 CC Network Security Practice Question
A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?
⚠ Common exam trap
CC often tests the misconception that VLANs eliminate IP addressing or increase collision domains, so candidates who confuse collision and broadcast domains pick the wrong options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They allow logical grouping of users regardless of physical location
Option A is correct because VLANs are Layer 2 logical constructs that let you group users by function, department, or role rather than by their physical switch port or building location, so a user in one office can belong to the same VLAN as a colleague elsewhere. Option D is correct because each VLAN forms its own broadcast domain, so broadcasts are confined to the VLAN's member ports instead of flooding the entire switched network, thereby reducing broadcast traffic. Option E is correct because placing sensitive systems (for example, servers holding regulated data) in a dedicated VLAN lets you control inter-VLAN traffic with Layer 3 filtering, ACLs, or a firewall, isolating them from general user traffic. Option B is not correct because VLANs operate at Layer 2 and still require Layer 3 addressing (IP subnets) for inter-VLAN routing and end-to-end communication. Option C is not correct because VLANs actually shrink collision domains (each switch port is its own collision domain) and divide broadcast domains; they do not increase the collision domain size.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They allow logical grouping of users regardless of physical location
Why this is correct
VLANs decouple broadcast domains from physical switch ports, so membership follows configuration rather than cabling. This satisfies the stem's benefit of grouping users logically irrespective of physical location, letting a department span floors or buildings while remaining one isolated Layer 2 segment.
- ✗
They eliminate the need for IP addressing
Why it's wrong here
VLANs operate at Layer 2 and still require IP addressing for inter-VLAN routing, so they cannot remove that need. The option is tempting because VLANs do let you reuse address space across isolated segments, which candidates mistake for eliminating addressing altogether.
- ✗
They increase the collision domain size
Why it's wrong here
VLANs shrink collision domains by placing each port in its own broadcast domain; they never enlarge one. The option is tempting because VLANs do extend the broadcast domain across multiple switches, and candidates confuse that broadcast-scope growth with collision-domain behaviour.
- ✓
They reduce broadcast traffic by dividing broadcast domains
Why this is correct
Each VLAN forms its own broadcast domain, so ARP requests and other broadcasts stay within that segment rather than flooding every switch port. Splitting one large domain into smaller ones cuts broadcast volume proportionally, which is the segmentation benefit described.
- ✓
They can isolate sensitive systems from the rest of the network
Why this is correct
VLANs logically partition a switched network, so sensitive hosts sit in their own broadcast domain with no Layer 2 path to other segments. Traffic between VLANs must traverse a router or firewall, where access control lists can enforce the isolation the scenario requires.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
Key term
Network segmentation
Network segmentation is the practice of dividing a computer network into smaller, isolated parts to improve performance, contain security threats, and simplify management.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.