easyMultiple Choice
ISC2 CC Practice Question: Is a primary benefit of implementing network…
Which of the following is a primary benefit of implementing network segmentation?
⚠ Common exam trap
ISC2 often tests the misconception that segmentation eliminates the need for firewalls, but in reality, segmentation and firewalls are complementary—firewalls enforce the segmentation policy, and segmentation reduces the attack surface by limiting exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduced attack surface
Network segmentation divides a network into smaller, isolated segments, which limits an attacker's ability to move laterally after compromising a single host. By restricting traffic between segments using VLANs, ACLs, or firewall rules, the attack surface is reduced because fewer systems are exposed to potential threats. This is a primary security benefit, as it contains breaches and minimizes the impact of malware or unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reduced attack surface
Why this is correct
Segmenting the network into isolated zones limits lateral movement, so a compromised host cannot reach unrelated systems. This directly shrinks the number of exploitable entry points and reachable targets, satisfying the requirement to reduce the attack surface.
- ✗
Eliminates the need for firewalls
Why it's wrong here
Segmentation works alongside firewalls, since inter-segment traffic must still be filtered by policy; removing firewalls would leave zones able to reach each other freely. It tempts because segmentation reduces the blast radius a firewall must defend, but the concrete benefit is containment of lateral movement, not firewall elimination.
- ✗
Increased bandwidth
Why it's wrong here
Segmentation partitions traffic into separate broadcast domains and filtered paths; it does not add link capacity or throughput. It tempts because smaller broadcast domains can reduce unnecessary traffic, but the primary benefit is limiting lateral movement and containing breaches, not raising raw bandwidth.
- ✗
Simplified IP address management
Why it's wrong here
Network segmentation partitions a network into isolated subnets, typically using VLANs or firewalls, to contain lateral movement and limit breach scope. Simplified IP address management is a benefit of DHCP or IPAM, not segmentation; those tools centralise address allocation and reduce manual configuration errors. Segmentation can actually complicate addressing by introducing additional subnets and gateways.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.