Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

⚠ Common exam trap

Watch out — candidates often confuse security controls (firewalls, IDS) with segmentation techniques — candidates often select firewalls because they 'segment' traffic, but the question asks for methods that create the segments themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Subnetting

Subnetting (A) is correct because dividing a larger IP network into smaller logical subnets using CIDR and subnet masks creates distinct broadcast domains and limits lateral movement between segments. DMZs (B) are correct because a demilitarized zone places internet-facing services such as web, mail, or DNS servers in a separate screened segment, isolating them from the internal trusted network. VLANs (D) are correct because IEEE 802.1Q VLANs logically segment a switched network at Layer 2, allowing departments or device groups to be separated without physical rewiring and enforcing traffic isolation via trunk and access port configuration. Firewalls (C) are not a segmentation method themselves; they are policy enforcement devices that control traffic between segments, so they are typically deployed to secure segmentation rather than create it. Intrusion Detection Systems (E) are monitoring tools that detect malicious activity and generate alerts, but they do not divide or isolate network segments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Subnetting

    Why this is correct

    Subnetting divides an IP network into smaller logical ranges at Layer 3, using the subnet mask to separate address blocks. Each subnet forms its own broadcast domain, and inter-subnet traffic must route through a gateway, enabling policy enforcement and limiting breach propagation.

  • ✓

    DMZs

    Why this is correct

    DMZs (Demilitarised Zones) are a fundamental method for network segmentation, specifically designed to host public-facing services like web or email servers. They create an isolated buffer network between an untrusted external network (e.g., the internet) and the organisation's trusted internal network. This isolation, enforced by firewalls, significantly improves security by preventing direct access to internal resources if a DMZ server is compromised, thereby satisfying the scenario's goal.

  • ✗

    Firewalls

    Why it's wrong here

    Firewalls filter traffic between zones but do not by themselves create the isolated segments; segmentation is achieved by dividing the network into VLANs or subnets, with firewalls controlling flows between them. Firewalls tempt because they enforce policy at segment boundaries.

  • ✓

    VLANs

    Why this is correct

    VLANs segment a switched network at Layer 2 by logically grouping ports into separate broadcast domains, regardless of physical location. Traffic between VLANs must pass through a Layer 3 device, so the segmentation enforces policy boundaries and limits lateral movement within the organisation.

  • ✗

    Intrusion Detection Systems

    Why it's wrong here

    Intrusion Detection Systems monitor traffic for malicious activity; they do not partition a network into isolated segments. It is tempting because IDS is a network security control often deployed alongside segmentation, and it would be the correct choice when the requirement is detecting attacks rather than dividing the network into separate zones.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.