Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

⚠ Common exam trap

CC often tests the misconception that VLANs eliminate IP addressing or increase collision domains, so candidates who confuse collision and broadcast domains pick the wrong options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They allow logical grouping of users regardless of physical location

Option A is correct because VLANs are Layer 2 logical constructs that let you group users by function, department, or role rather than by their physical switch port or building location, so a user in one office can belong to the same VLAN as a colleague elsewhere. Option D is correct because each VLAN forms its own broadcast domain, so broadcasts are confined to the VLAN's member ports instead of flooding the entire switched network, thereby reducing broadcast traffic. Option E is correct because placing sensitive systems (for example, servers holding regulated data) in a dedicated VLAN lets you control inter-VLAN traffic with Layer 3 filtering, ACLs, or a firewall, isolating them from general user traffic. Option B is not correct because VLANs operate at Layer 2 and still require Layer 3 addressing (IP subnets) for inter-VLAN routing and end-to-end communication. Option C is not correct because VLANs actually shrink collision domains (each switch port is its own collision domain) and divide broadcast domains; they do not increase the collision domain size.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    They allow logical grouping of users regardless of physical location

    Why this is correct

    VLANs decouple broadcast domains from physical switch ports, so membership follows configuration rather than cabling. This satisfies the stem's benefit of grouping users logically irrespective of physical location, letting a department span floors or buildings while remaining one isolated Layer 2 segment.

  • ✗

    They eliminate the need for IP addressing

    Why it's wrong here

    VLANs operate at Layer 2 and still require IP addressing for inter-VLAN routing, so they cannot remove that need. The option is tempting because VLANs do let you reuse address space across isolated segments, which candidates mistake for eliminating addressing altogether.

  • ✗

    They increase the collision domain size

    Why it's wrong here

    VLANs shrink collision domains by placing each port in its own broadcast domain; they never enlarge one. The option is tempting because VLANs do extend the broadcast domain across multiple switches, and candidates confuse that broadcast-scope growth with collision-domain behaviour.

  • ✓

    They reduce broadcast traffic by dividing broadcast domains

    Why this is correct

    Each VLAN forms its own broadcast domain, so ARP requests and other broadcasts stay within that segment rather than flooding every switch port. Splitting one large domain into smaller ones cuts broadcast volume proportionally, which is the segmentation benefit described.

  • ✓

    They can isolate sensitive systems from the rest of the network

    Why this is correct

    VLANs logically partition a switched network, so sensitive hosts sit in their own broadcast domain with no Layer 2 path to other segments. Traffic between VLANs must traverse a router or firewall, where access control lists can enforce the isolation the scenario requires.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.