ISC2 CC Network Security Practice Question
An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?
⚠ Common exam trap
Many exam-takers confuse Layer 2 segmentation (VLAN) with Layer 3 segmentation (subnetting) — candidates often pick 'Subnetting' because both provide logical separation, but only VLANs create separate broadcast domains on a single switch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VLAN
A VLAN (Virtual Local Area Network) logically partitions a single physical switch into multiple separate broadcast domains. Each VLAN operates as its own Layer 2 network, and broadcast traffic from one VLAN is not forwarded to another without a Layer 3 device. This is the standard technology for network segmentation at Layer 2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DMZ
Why it's wrong here
Separate broadcast domains on one switch are created by VLANs, which partition the switch into isolated Layer 2 segments; a DMZ is a perimeter subnet exposing public-facing services to untrusted networks, typically built using firewalls and separate physical or virtual network segments rather than switch-level broadcast domain separation.
- ✗
Honeypot
Why it's wrong here
A honeypot is a decoy system deployed to lure and observe attackers, offering no broadcast-domain separation. It would be the right choice for threat detection and intelligence gathering, not for segmenting traffic on a switch.
- ✗
Subnetting
Why it's wrong here
Subnetting divides an IP network at Layer 3, but broadcast domains are separated by VLANs at Layer 2 on a single switch. Subnetting would be correct when partitioning address space for routing and IP management.
- ✓
VLAN
Why this is correct
VLANs logically partition one physical switch into isolated Layer 2 broadcast domains, so broadcasts stay within each segment rather than flooding every port. This directly satisfies the stem's requirement for separate broadcast domains on a single switch, unlike subnetting (Layer 3) or physical segmentation, which would need additional hardware.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Network segmentation
Network segmentation is the practice of dividing a computer network into smaller, isolated parts to improve performance, contain security threats, and simplify management.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.