CISSP Communication and Network Security Practice Question
A security architect is designing a network segmentation strategy for a financial institution. Which TWO techniques are best suited for implementing micro-segmentation in a data center environment? (Select two.)
⚠ Common exam trap
Candidates often confuse traditional network segmentation (such as VLANs or physical firewalls) with micro-segmentation. While VLANs segment networks at Layer 2, they lack the granularity, scalability, and dynamic policy enforcement required for workload-level (micro) isolation in a cloud or virtualized data center.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software-Defined Networking (SDN)
Software-Defined Networking (SDN) is correct because it centralizes control-plane policy and lets the architect program granular, workload-level segmentation rules (e.g., via OpenFlow or APIs) that can be applied dynamically across the data center fabric, which is essential for micro-segmentation. Hypervisor-based firewalls are correct because they enforce Layer 2–4 (and often Layer 7) policy directly at the virtual NIC of each VM, enabling per-workload isolation and east-west traffic control without relying on physical topology. VLANs are not the best fit because they provide coarse Layer 2 broadcast-domain separation (limited to ~4094 IDs) rather than fine-grained per-workload policy. Physical network firewalls are too coarse and chokepoint-oriented for micro-segmentation, as they cannot practically enforce policy between every workload pair. A DMZ (screened subnet) is a perimeter segmentation pattern for exposing services to untrusted networks, not an east-west micro-segmentation technique inside the data center.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VLANs (Virtual Local Area Networks)
Why it's wrong here
VLANs (Virtual Local Area Networks) segment networks at Layer 2 by creating separate broadcast domains, but they are not granular enough for micro-segmentation. All devices within a single VLAN can still communicate freely, meaning a compromise of one workload could spread to others in the same VLAN. This approach lacks the per-workload isolation needed for modern zero-trust architectures within a data center.
- ✓
Software-Defined Networking (SDN)
Why this is correct
Software-Defined Networking (SDN) provides dynamic, centralized control over network infrastructure, enabling highly granular security policies. By decoupling the control plane from the data plane, SDN controllers can define and enforce per-application or per-workload segmentation policies, often leveraging virtual switches to isolate East-West traffic. This allows for flexible, identity-based security that adapts to changing application requirements.
- ✓
Hypervisor-based firewalls
Why this is correct
Hypervisor-based firewalls are integrated directly into the virtualization layer, allowing them to inspect and filter traffic between virtual machines (VMs) on the same physical host. This provides extremely granular East-West traffic segmentation at the virtual network interface card (vNIC) or VM level, preventing lateral movement even before traffic leaves the host. They are highly effective for isolating individual workloads within a virtualized data center.
- ✗
Physical network firewalls
Why it's wrong here
Physical network firewalls are designed primarily for perimeter defense or coarse-grained segmentation between large network zones. Routing all East-West traffic between individual virtual machines through a centralized physical firewall would introduce significant latency and create a severe bottleneck. Their deployment model is not scalable or cost-effective for the fine-grained, per-workload isolation required by micro-segmentation within a dynamic data center.
- ✗
DMZ (screened subnet)
Why it's wrong here
A DMZ (Demilitarized Zone) is a network architecture designed to host public-facing services, isolating them from the internal trusted network. It provides macro-level segmentation, acting as a buffer between an untrusted external network and a trusted internal one. However, a DMZ does not offer the granular, internal segmentation capabilities required to isolate individual applications or workloads from each other *within* a data center.
Visual reference
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.