Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Is a primary benefit of implementing network…

Which of the following is a primary benefit of implementing network segmentation?

⚠ Common exam trap

ISC2 often tests the misconception that segmentation eliminates the need for firewalls, but in reality, segmentation and firewalls are complementary—firewalls enforce the segmentation policy, and segmentation reduces the attack surface by limiting exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduced attack surface

Network segmentation divides a network into smaller, isolated segments, which limits an attacker's ability to move laterally after compromising a single host. By restricting traffic between segments using VLANs, ACLs, or firewall rules, the attack surface is reduced because fewer systems are exposed to potential threats. This is a primary security benefit, as it contains breaches and minimizes the impact of malware or unauthorized access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reduced attack surface

    Why this is correct

    Segmenting the network into isolated zones limits lateral movement, so a compromised host cannot reach unrelated systems. This directly shrinks the number of exploitable entry points and reachable targets, satisfying the requirement to reduce the attack surface.

  • ✗

    Eliminates the need for firewalls

    Why it's wrong here

    Segmentation works alongside firewalls, since inter-segment traffic must still be filtered by policy; removing firewalls would leave zones able to reach each other freely. It tempts because segmentation reduces the blast radius a firewall must defend, but the concrete benefit is containment of lateral movement, not firewall elimination.

  • ✗

    Increased bandwidth

    Why it's wrong here

    Segmentation partitions traffic into separate broadcast domains and filtered paths; it does not add link capacity or throughput. It tempts because smaller broadcast domains can reduce unnecessary traffic, but the primary benefit is limiting lateral movement and containing breaches, not raising raw bandwidth.

  • ✗

    Simplified IP address management

    Why it's wrong here

    Network segmentation partitions a network into isolated subnets, typically using VLANs or firewalls, to contain lateral movement and limit breach scope. Simplified IP address management is a benefit of DHCP or IPAM, not segmentation; those tools centralise address allocation and reduce manual configuration errors. Segmentation can actually complicate addressing by introducing additional subnets and gateways.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.