ISC2 CC Network Security Practice Question
An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)
⚠ Common exam trap
Watch out — candidates often confuse security controls (firewalls, IDS) with segmentation techniques — candidates often select firewalls because they 'segment' traffic, but the question asks for methods that create the segments themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Subnetting
Subnetting (A) is correct because dividing a larger IP network into smaller logical subnets using CIDR and subnet masks creates distinct broadcast domains and limits lateral movement between segments. DMZs (B) are correct because a demilitarized zone places internet-facing services such as web, mail, or DNS servers in a separate screened segment, isolating them from the internal trusted network. VLANs (D) are correct because IEEE 802.1Q VLANs logically segment a switched network at Layer 2, allowing departments or device groups to be separated without physical rewiring and enforcing traffic isolation via trunk and access port configuration. Firewalls (C) are not a segmentation method themselves; they are policy enforcement devices that control traffic between segments, so they are typically deployed to secure segmentation rather than create it. Intrusion Detection Systems (E) are monitoring tools that detect malicious activity and generate alerts, but they do not divide or isolate network segments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Subnetting
Why this is correct
Subnetting divides an IP network into smaller logical ranges at Layer 3, using the subnet mask to separate address blocks. Each subnet forms its own broadcast domain, and inter-subnet traffic must route through a gateway, enabling policy enforcement and limiting breach propagation.
- ✓
DMZs
Why this is correct
DMZs (Demilitarised Zones) are a fundamental method for network segmentation, specifically designed to host public-facing services like web or email servers. They create an isolated buffer network between an untrusted external network (e.g., the internet) and the organisation's trusted internal network. This isolation, enforced by firewalls, significantly improves security by preventing direct access to internal resources if a DMZ server is compromised, thereby satisfying the scenario's goal.
- ✗
Firewalls
Why it's wrong here
Firewalls filter traffic between zones but do not by themselves create the isolated segments; segmentation is achieved by dividing the network into VLANs or subnets, with firewalls controlling flows between them. Firewalls tempt because they enforce policy at segment boundaries.
- ✓
VLANs
Why this is correct
VLANs segment a switched network at Layer 2 by logically grouping ports into separate broadcast domains, regardless of physical location. Traffic between VLANs must pass through a Layer 3 device, so the segmentation enforces policy boundaries and limits lateral movement within the organisation.
- ✗
Intrusion Detection Systems
Why it's wrong here
Intrusion Detection Systems monitor traffic for malicious activity; they do not partition a network into isolated segments. It is tempting because IDS is a network security control often deployed alongside segmentation, and it would be the correct choice when the requirement is detecting attacks rather than dividing the network into separate zones.
Visual reference
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.