ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
A security architect is designing a network for a new high-security research facility. The facility will have multiple departments, each handling sensitive and distinct research data. The architect needs to ensure that traffic from one department cannot directly access resources in another department without passing through a central security inspection point, even if they are on the same physical switch. Which of the following network segmentation techniques is BEST suited for this requirement?
- AVirtual Local Area Network (VLAN)
- BSubnetting
- CQuality of Service (QoS)
- DNetwork Address Translation (NAT)
Show answer & explanationAnswer & explanation
Correct answer: A. Virtual Local Area Network (VLAN)
VLANs provide logical segmentation of a network, allowing different departments to be isolated even if they share the same physical network infrastructure. This segregation enforces that inter-VLAN traffic must traverse a Layer 3 device, which can be configured as a security inspection point.
Why the other options are wrong
- B. Subnetting provides logical separation at Layer 3 but doesn't inherently prevent direct communication between hosts on the same physical segment without a router.
- C. QoS prioritizes network traffic but does not provide security isolation or segmentation.
- D. NAT translates IP addresses but does not provide network segmentation or isolation between internal departments.
Virtual Local Area Network (VLAN)
A logical grouping of network devices that allows for network segmentation at Layer 2, independent of physical location. VLANs isolate broadcast domains and improve security by controlling inter-VLAN communication.
- Segments a single physical network into multiple logical networks.
- Requires a Layer 3 device (router/firewall) for inter-VLAN routing.
- Enhances security and network performance by reducing broadcast traffic.
Memory trick: Virtual Lines Always Isolate Networks Securely.