SSCP Network and Communications Security Practice Question
A company is designing a network with multiple security zones. Which TWO of the following are best practices for network segmentation? (Select TWO)
⚠ Common exam trap
Watch out — candidates often confuse 'reducing complexity' with security best practice — flat networks are simpler but insecure, and candidates may pick them under time pressure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place a firewall between each security zone to enforce traffic filtering.
Option A is correct because placing a firewall between each security zone enforces traffic filtering and access control at zone boundaries, which is the core principle of defense-in-depth segmentation — inter-zone traffic should be inspected and permitted only per policy rather than flowing freely. Option C is correct because VLANs (IEEE 802.1Q) logically separate traffic at Layer 2 within a switch, limiting broadcast domains and isolating hosts even when they share physical infrastructure, which is a standard segmentation technique. Option B is wrong because a single flat network removes all segmentation boundaries, allowing unrestricted lateral movement and broadcast propagation. Option D is wrong because disabling logging on inter-zone firewalls destroys the audit trail and visibility needed to detect and investigate policy violations. Option E is wrong because putting all servers in one broadcast domain increases attack surface and broadcast traffic, directly contradicting segmentation best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place a firewall between each security zone to enforce traffic filtering.
Why this is correct
Placing a firewall between each zone enforces traffic filtering at every boundary, satisfying the segmentation requirement by preventing unrestricted lateral movement. Inter-zone traffic is inspected and permitted only per policy, containing breaches within a single zone.
- ✗
Use a single flat network to reduce complexity.
Why it's wrong here
A single flat network gives every host direct layer-2 reachability to every other, so no policy enforcement point exists between zones. Flat designs are genuinely appropriate for tiny isolated environments. Segmentation instead requires distinct VLANs or subnets per zone, with firewalls or ACLs controlling inter-zone traffic.
- ✓
Implement VLANs to logically separate traffic within a switch.
Why this is correct
VLANs logically separate traffic within a switch, satisfying the segmentation requirement by isolating broadcast domains and restricting Layer 2 reachability between groups. Traffic between VLANs must route through a Layer 3 device, where filtering policy can be applied.
- ✗
Disable logging on inter-zone firewalls to improve performance.
Why it's wrong here
Disabling inter-zone firewall logging removes the audit trail needed to detect lateral movement between security zones, directly undermining segmentation monitoring. It is tempting because logging does consume firewall CPU and storage, so teams disable it under load; logging would only be acceptable where no compliance or forensic requirement exists.
- ✗
Place all servers in the same broadcast domain for easier management.
Why it's wrong here
Pooling all servers into one broadcast domain removes the inter-zone filtering that segmentation exists to provide, so a single compromised host can reach every peer. A shared broadcast domain is genuinely appropriate for small trusted labs. Best practice instead groups servers by function and sensitivity into separate VLANs with enforced ACLs.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.