A security engineer is designing a network segmentation strategy to isolate a DMZ containing public-facing web servers from the internal corporate network. Which TWO controls should be implemented? (Select two)
Separate VLANs provide Layer 2 isolation, ensuring broadcast traffic and direct frame-level communication cannot pass between the DMZ web servers and internal hosts. This satisfies the segmentation requirement by enforcing distinct logical network boundaries, with inter-VLAN routing then controlled by a firewall applying least-privilege rules.
Why this answer
Option A is correct because placing the DMZ and internal network in separate VLANs provides Layer 2 segmentation, preventing broadcast traffic and direct frame-level communication between the two zones unless explicitly routed through a Layer 3 device. Option B is correct because a firewall enforcing least privilege between zones is the core segmentation control: it allows only required inbound traffic (e.g., TCP 443 to the web servers) into the DMZ and restricts outbound DMZ-to-internal traffic, blocking lateral movement if a public-facing server is compromised. Option D is not sufficient on its own because a separate IP subnet alone does not enforce traffic filtering; routing between subnets can still occur without a firewall policy.
Option C does not belong because NAC controls endpoint admission to the network and does not segment an existing DMZ from the internal network. Option E does not belong because an IDS only monitors and alerts on traffic; it does not enforce segmentation or block unauthorized flows.
Exam trap
SSCP often tests the difference between preventive and detective controls, and candidates may select IDS or NAC as segmentation controls when they are not.