CompTIA CySA+ (CS0-003)Security OperationsEasy
A network administrator wants to isolate broadcast traffic between the finance and HR departments so that a compromised host or broadcast storm in one department cannot directly affect devices in the other, without installing additional physical switches. Which technology should be implemented?
- ALoad balancer
- BNAT
- CSite-to-site VPN
- DVLAN
Show answer & explanationAnswer & explanation
Correct answer: D. VLAN
A VLAN logically segments a switch into separate broadcast domains at Layer 2, allowing finance and HR traffic to be isolated on the same physical infrastructure. NAT translates addresses, VPNs secure traffic over untrusted networks, and load balancers distribute traffic across servers.
Why the other options are wrong
- A. Load balancers distribute traffic to servers, not isolate departments.
- B. NAT is used for address translation, not broadcast domain isolation.
- C. VPNs secure remote connections, not internal LAN segmentation.
VLAN Segmentation
A Virtual Local Area Network logically divides a physical switch into multiple isolated broadcast domains, restricting traffic between groups of devices without requiring separate physical switches.
- VLANs operate at OSI Layer 2 using tagging (802.1Q)
- Inter-VLAN traffic requires a router or Layer 3 switch
- Reduces attack surface by limiting lateral broadcast/ARP traffic
Memory trick: 'V for Virtual walls' - VLAN builds invisible walls inside one switch.