Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)

⚠ Common exam trap

The trap here is relying on detection or obscurity controls like IDS or NAT instead of preventive access controls that actually restrict connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the database server in a separate VLAN and configure firewall rules to allow traffic only from the application server's IP address.

Combining network segmentation with firewall rules and a host-based firewall provides defense in depth. The VLAN and network firewall restrict access at the network perimeter, while the host firewall adds protection directly on the server. Together, they ensure only the application server can connect, aligning with least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the database server in a separate VLAN and configure firewall rules to allow traffic only from the application server's IP address.

    Why this is correct

    Segmenting the database server into its own VLAN isolates it at the network layer, and firewall rules restrict access to only the application server. This combination enforces least privilege and reduces the attack surface. It ensures that even if other systems are compromised, they cannot directly reach the database.

  • ✗

    Use network address translation (NAT) to hide the database server's IP address from other internal systems.

    Why it's wrong here

    NAT hides internal IP addresses from external networks, but within the internal network, systems can still route to the database server's real IP unless additional controls are in place. NAT is not an access control mechanism. It does not restrict which internal systems can initiate connections, so it fails to meet the requirement.

  • ✗

    Enable port security on the switch port connected to the database server to restrict MAC addresses.

    Why it's wrong here

    Port security restricts which MAC addresses can connect to a switch port, preventing MAC flooding and unauthorized devices. However, it does not control IP-layer access. An attacker on an allowed MAC address could still initiate connections. It does not enforce that only the application server can connect based on IP, so it does not meet the requirement.

  • ✗

    Deploy an intrusion detection system (IDS) to monitor traffic to the database server and alert on suspicious connections.

    Why it's wrong here

    An IDS detects and alerts on potential intrusions but does not prevent them. It is a monitoring tool, not an access control. While it can provide visibility, it does not block unauthorized connections. The requirement is to ensure only the application server can connect, which requires preventive controls, not just detection.

  • ✓

    Implement a host-based firewall on the database server that allows connections only from the application server's IP address.

    Why this is correct

    A host-based firewall provides an additional layer of defense directly on the database server. Even if network segmentation is bypassed, the host firewall blocks unauthorized connections. Configuring it to allow only the application server's IP ensures that only the intended system can connect, enforcing the principle of least privilege.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.