Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Has multiple network segments for accounting, HR,…

An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?

⚠ Common exam trap

ISC2 often tests the distinction between passive detection (IDS) and active prevention (firewall/ACL), so candidates mistakenly choose IDS thinking it blocks traffic, but it only alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLAN segmentation with ACLs

VLAN segmentation with ACLs is the correct choice because VLANs create separate broadcast domains at Layer 2, isolating traffic between network segments (accounting, HR, engineering). ACLs applied to the Layer 3 interface (SVI) or trunk ports then enforce granular rules to permit only necessary inter-VLAN communication, such as allowing HR to access a shared server while blocking all other cross-segment traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VLAN segmentation with ACLs

    Why this is correct

    VLANs logically separate the accounting, HR and engineering segments at layer 2, and ACLs on the router or switch filter inter-VLAN traffic, permitting only authorised flows. This satisfies the constraint of blocking unauthorised traffic between segments while allowing necessary communication, which flat subnetting cannot achieve.

  • ✗

    Intrusion Detection System (IDS)

    Why it's wrong here

    An IDS only detects and alerts on malicious activity; it sits passively on mirrored traffic and cannot block unauthorised inter-segment communication. It is tempting because it monitors traffic across segments, and would be correct where the requirement is visibility and alerting on intrusions rather than enforcement.

  • ✗

    Proxy server

    Why it's wrong here

    A proxy server brokers application-layer requests, typically HTTP, rather than enforcing segment-to-segment packet filtering, so it cannot block arbitrary inter-segment traffic. It is tempting because proxies do mediate and inspect traffic, and would be the right control for controlling outbound web access or caching content for internal users.

  • ✗

    Honeypot

    Why it's wrong here

    A honeypot is a decoy system that lures and observes attackers; it cannot block traffic between segments. A firewall or microsegmentation enforces that control. Honeypots are tempting because they are a security control that detects intrusion attempts, but they provide detection and intelligence rather than the prevention this requirement demands.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.