CompTIA Security+ (SY0-701)Security ArchitectureMedium

A network administrator is redesigning a corporate office network. Guest Wi-Fi users, employee workstations, and VoIP phones must all be logically separated so that a compromise on one group cannot directly reach the others, while sharing the same physical switches. Which technology BEST accomplishes this?

  1. ANetwork address translation
  2. BVLANs with inter-VLAN access control lists
  3. CPort security based on MAC address
  4. DA single flat subnet with a host-based firewall on each device
Show answer & explanation

Correct answer: B. VLANs with inter-VLAN access control lists

VLANs logically segment traffic on shared physical switches, and applying ACLs between VLANs enforces which groups can communicate, limiting lateral movement between guest, employee, and VoIP segments.

Why the other options are wrong

  • A. NAT translates addresses for routing to the internet; it does not segment internal traffic groups.
  • C. Port security limits which MAC addresses can use a port but does not segment traffic types.
  • D. A flat subnet still allows broadcast/layer-2 reachability between all devices regardless of host firewalls.

VLAN Segmentation

A method of logically dividing a physical network into separate broadcast domains to isolate traffic between groups of devices.

  • Reduces attack surface by limiting broadcast/lateral movement
  • Often combined with ACLs or firewalls for inter-VLAN traffic control
  • Common segments: guest, voice, data, management

Memory trick: 'Different rooms, same building — VLANs are virtual walls.'

More Security Architecture questions