ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium

A security architect is designing the network for a new high-security research facility. The facility requires strict network segmentation, where different research projects must be completely isolated from each other at Layer 2, even if they share the same physical switch infrastructure. Additionally, the design must logically separate administrative traffic from user data traffic. Which technology is MOST effective for achieving this logical Layer 2 segmentation?

  1. ANetwork Access Control (NAC)
  2. BVirtual Local Area Networks (VLANs)
  3. CSubnetting
  4. DFirewall Rules
Show answer & explanation

Correct answer: B. Virtual Local Area Networks (VLANs)

VLANs provide logical Layer 2 segmentation, allowing devices on the same physical switch to be separated into different broadcast domains. This effectively isolates traffic between different projects and administrative/user traffic, meeting the requirements. Subnetting is Layer 3, firewalls filter traffic between segments, and NAC controls access.

Why the other options are wrong

  • A. Network Access Control (NAC) authenticates and authorizes devices connecting to the network, but it doesn't primarily create the logical Layer 2 segmentation itself.
  • C. Subnetting operates at Layer 3 (IP layer) and provides network segmentation, but not directly Layer 2 broadcast domain isolation on shared physical switches.
  • D. Firewall rules filter traffic between network segments (VLANs or subnets), but do not themselves create the Layer 2 segmentation.

Virtual Local Area Network (VLAN)

A logical grouping of network devices that allows for segmentation of a local area network (LAN) into multiple broadcast domains, even if devices are on the same physical switch.

  • Operates at Layer 2 of the OSI model.
  • Enhances security by isolating traffic.
  • Improves network performance by reducing broadcast traffic.

Memory trick: VLANs are 'Virtual Lanes' for traffic, keeping projects separated.

More Communication and Network Security questions