SSCP Network and Communications Security Practice Question
An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?
⚠ Common exam trap
The trap is selecting port security or NAT as segmentation methods — port security is port-level access control, and NAT is address translation, neither of which segments networks or enforces inter-segment policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewalls
Firewalls (C) are a core segmentation control because they enforce policy between zones—filtering traffic by IP address, port, and protocol (e.g., allowing only TCP 443 from a DMZ to an internal subnet)—thereby restricting lateral movement toward sensitive data. VLANs (E) segment a switched network at Layer 2 by logically isolating broadcast domains, so hosts in different VLANs cannot communicate directly without a Layer 3 device, which is a standard way to separate sensitive systems from general user traffic. Honeypots (A) are deception/detection decoys, not segmentation mechanisms, since they attract and log attackers rather than partition traffic. NAT (B) translates addresses (e.g., private RFC 1918 to public) for connectivity and concealment, but it does not by itself enforce segmentation between internal zones. Port security (D) limits which MAC addresses may use a switch port to prevent unauthorized devices or MAC flooding, but it does not create separate network segments or control inter-zone traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Honeypots
Why it's wrong here
Honeypots are decoy systems that detect and study attackers; they neither divide a network nor restrict traffic between zones. They are tempting because they are security controls placed inside segmented environments, but segmentation itself needs VLANs, subnets, firewalls or ACLs.
- ✗
NAT
Why it's wrong here
NAT translates addresses between internal and external networks; it does not partition a network into isolated zones or enforce traffic policy between segments. It is tempting because NAT hides internal addressing, but segmentation requires VLANs, subnets, firewalls or ACLs controlling inter-zone flows.
- ✓
Firewalls
Why this is correct
Firewalls enforce segmentation by inspecting traffic and permitting or denying flows between network zones according to rule sets, so sensitive-data segments stay isolated from untrusted areas. They satisfy the stem's requirement for an effective segmentation method by providing policy-based control at zone boundaries.
- ✗
Port security
Why it's wrong here
Port security limits which MAC addresses may use a switch port, preventing unauthorised device attachment at Layer 2; it does not create isolated network zones. It is tempting because it is a switch-level control, but segmentation requires VLANs, subnets, firewalls or ACLs separating traffic.
- ✓
VLANs
Why this is correct
VLANs segment a switched network at Layer 2 by assigning ports to isolated broadcast domains, so sensitive hosts cannot communicate directly with other segments without routing. This satisfies the segmentation requirement by containing traffic and enforcing boundaries between groups of systems.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.