Courseiva

SSCP Network and Communications Security Practice Question

An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?

⚠ Common exam trap

The trap is selecting port security or NAT as segmentation methods — port security is port-level access control, and NAT is address translation, neither of which segments networks or enforces inter-segment policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Firewalls

Firewalls (C) are a core segmentation control because they enforce policy between zones—filtering traffic by IP address, port, and protocol (e.g., allowing only TCP 443 from a DMZ to an internal subnet)—thereby restricting lateral movement toward sensitive data. VLANs (E) segment a switched network at Layer 2 by logically isolating broadcast domains, so hosts in different VLANs cannot communicate directly without a Layer 3 device, which is a standard way to separate sensitive systems from general user traffic. Honeypots (A) are deception/detection decoys, not segmentation mechanisms, since they attract and log attackers rather than partition traffic. NAT (B) translates addresses (e.g., private RFC 1918 to public) for connectivity and concealment, but it does not by itself enforce segmentation between internal zones. Port security (D) limits which MAC addresses may use a switch port to prevent unauthorized devices or MAC flooding, but it does not create separate network segments or control inter-zone traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Honeypots

    Why it's wrong here

    Honeypots are decoy systems that detect and study attackers; they neither divide a network nor restrict traffic between zones. They are tempting because they are security controls placed inside segmented environments, but segmentation itself needs VLANs, subnets, firewalls or ACLs.

  • ✗

    NAT

    Why it's wrong here

    NAT translates addresses between internal and external networks; it does not partition a network into isolated zones or enforce traffic policy between segments. It is tempting because NAT hides internal addressing, but segmentation requires VLANs, subnets, firewalls or ACLs controlling inter-zone flows.

  • ✓

    Firewalls

    Why this is correct

    Firewalls enforce segmentation by inspecting traffic and permitting or denying flows between network zones according to rule sets, so sensitive-data segments stay isolated from untrusted areas. They satisfy the stem's requirement for an effective segmentation method by providing policy-based control at zone boundaries.

  • ✗

    Port security

    Why it's wrong here

    Port security limits which MAC addresses may use a switch port, preventing unauthorised device attachment at Layer 2; it does not create isolated network zones. It is tempting because it is a switch-level control, but segmentation requires VLANs, subnets, firewalls or ACLs separating traffic.

  • ✓

    VLANs

    Why this is correct

    VLANs segment a switched network at Layer 2 by assigning ports to isolated broadcast domains, so sensitive hosts cannot communicate directly with other segments without routing. This satisfies the segmentation requirement by containing traffic and enforcing boundaries between groups of systems.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.