CompTIA Network+ (N10-009)Network SecurityHard

A hospital network architect wants to isolate medical IoT devices so that even if one device is compromised, an attacker cannot pivot laterally to access electronic health record servers or administrative workstations. The devices must still reach a central monitoring server. Which design approach BEST achieves this goal?

  1. AImplement network segmentation with a dedicated VLAN and firewall rules restricting IoT traffic to only the monitoring server
  2. BPlace all devices on the same VLAN with a shared default gateway
  3. CConfigure port security with a maximum of one MAC address per switchport
  4. DEnable STP root guard on all IoT switchports
Show answer & explanation

Correct answer: A. Implement network segmentation with a dedicated VLAN and firewall rules restricting IoT traffic to only the monitoring server

Network segmentation using a dedicated VLAN combined with firewall ACLs limiting traffic to only necessary destinations (the monitoring server) enforces least privilege and contains a compromise, preventing lateral movement to EHR servers or workstations.

Why the other options are wrong

  • B. Sharing a VLAN with other systems increases lateral movement risk rather than reducing it.
  • C. Port security prevents MAC spoofing/flooding but does not restrict where traffic can go on the network.
  • D. Root guard protects spanning-tree topology, not lateral traffic flow between segments.

Network Segmentation

Dividing a network into isolated zones (e.g., via VLANs and firewall rules) to limit the scope of a security breach and control traffic flow between zones.

  • Common in IoT/OT environments to isolate risky devices
  • Combines VLANs with firewall ACLs for enforcement
  • Reduces attack surface via lateral movement containment

Memory trick: Segments are like watertight compartments on a ship—one leak doesn't sink it all.

More Network Security questions