Courseiva

SSCP Network and Communications Security Practice Question

A network engineer is implementing a secure network design that requires separating the network into multiple segments to limit the scope of a potential breach. The engineer wants to ensure that even if one segment is compromised, the attacker cannot easily move laterally to other segments. Which of the following technologies should be implemented to achieve this?

⚠ Common exam trap

The trap here is assuming that any security technology that separates networks, such as a DMZ, provides the same internal segmentation as VLANs with ACLs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLAN segmentation with ACLs

VLAN segmentation combined with ACLs allows the network to be divided into isolated logical segments with controlled traffic between them. This limits lateral movement because an attacker in one VLAN cannot access other VLANs without passing through the ACLs, which can be configured to deny unauthorized traffic. Other options like NAT, DMZ, and VPN do not provide the same level of internal segmentation and access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network Address Translation (NAT)

    Why it's wrong here

    NAT translates private IP addresses to public ones, primarily for IP address conservation and to hide internal addressing. It does not provide segmentation or access control between internal network segments. An attacker who gains access to the internal network can still move laterally regardless of NAT. Thus, NAT does not fulfill the requirement for limiting lateral movement.

  • ✓

    VLAN segmentation with ACLs

    Why this is correct

    VLANs logically separate network traffic at Layer 2, and ACLs on routers or Layer 3 switches can control traffic between VLANs. This creates distinct security zones and restricts lateral movement. If one VLAN is compromised, the attacker cannot freely access other VLANs without passing through the ACLs. This provides a strong segmentation strategy that meets the requirement. Therefore, VLAN segmentation with ACLs is the correct choice.

  • ✗

    Demilitarized zone (DMZ)

    Why it's wrong here

    A DMZ is a subnetwork that exposes external-facing services to the internet while isolating them from the internal network. It is a form of segmentation, but it is designed to protect the internal network from external threats, not to segment internal networks from each other. It does not prevent lateral movement within the internal network. Therefore, a DMZ alone does not meet the segmentation requirement.

  • ✗

    Virtual Private Network (VPN)

    Why it's wrong here

    A VPN provides encrypted tunnels for remote access or site-to-site connectivity. It secures data in transit but does not segment a local network into isolated zones. It can be used to extend a network, but it does not inherently restrict lateral movement between internal segments. Thus, VPN is not the appropriate technology for internal network segmentation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.