ISC2 CC Network Security Practice Question
Which three of the following are benefits of using VLANs in a network? (Choose three.)
⚠ Common exam trap
The trap is selecting 'eliminates the need for routing' or 'increases collision domains' as benefits; the exam tests that VLANs require routing for inter-VLAN traffic and actually reduce collision domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enhanced security through network segmentation
Option A is correct because VLANs logically segment a physical switch into isolated broadcast domains, so traffic from one VLAN cannot reach another without a Layer 3 device (router or multilayer switch), which enforces policy and limits unauthorized access. Option D is correct because each VLAN is its own broadcast domain, so broadcasts are confined to the ports assigned to that VLAN rather than flooding the entire switched network, reducing overall broadcast traffic. Option E is correct because VLAN membership is a logical configuration, so when a user relocates, an administrator can reassign the port or use dynamic VLAN assignment (e.g., via 802.1Q or VMPS) instead of physically rewiring or moving the user to a different switch. Option B is not correct because inter-VLAN communication still requires Layer 3 routing (router-on-a-stick, SVIs, or a Layer 3 switch), so routing is not eliminated. Option C is not correct because VLANs actually reduce the size of broadcast domains and do not increase collision domains; collision domains are determined by switch ports and full-duplex links, not by VLAN creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enhanced security through network segmentation
Why this is correct
VLANs logically partition one physical switch fabric into isolated broadcast domains, so hosts in different VLANs cannot reach each other without a Layer 3 device. This segmentation satisfies the stem's security benefit by containing reconnaissance and limiting lateral movement between departments.
- ✗
Eliminates the need for routing
Why it's wrong here
VLANs segment broadcast domains but still require Layer 3 routing for inter-VLAN traffic, so routing is not eliminated. It is tempting because VLANs reduce broadcast traffic and logically separate networks, which feels like removing routing, yet communication between VLANs depends on a router or Layer 3 switch.
- ✗
Increased collision domains
Why it's wrong here
VLANs segment one switch into separate broadcast domains, reducing collision domains rather than increasing them; each port remains its own collision domain. It is tempting because VLANs genuinely shrink broadcast scope and improve performance, which sounds like more collision domains, but the mechanism is broadcast separation.
- ✓
Reduction of broadcast traffic
Why this is correct
Each VLAN forms its own broadcast domain, so ARP requests and other broadcasts stay within that VLAN rather than flooding every switch port. Splitting one flat network into several VLANs therefore cuts the volume of broadcast traffic each host must process.
- ✓
Simplified network administration when users move
Why this is correct
VLAN membership follows logical configuration rather than physical switch port, so relocating a user to another desk or floor keeps their existing VLAN assignment without recabling or reconfiguring the access switch. This directly satisfies the stem's administration benefit, since moves, adds and changes become software edits instead of physical patching work.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.