ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

A large enterprise is designing a new campus network and needs to segment different departments to enhance security and manage broadcast domains efficiently. Each department requires its own logical network, but the physical infrastructure should remain shared to reduce costs. Which technology would best achieve this segmentation?

  1. ANetwork Address Translation (NAT)
  2. BVirtual Private Network (VPN)
  3. CDemilitarized Zone (DMZ)
  4. DVirtual Local Area Network (VLAN)
Show answer & explanation

Correct answer: D. Virtual Local Area Network (VLAN)

VLANs allow network administrators to segment a single physical network into multiple logical networks, effectively creating separate broadcast domains for different departments while sharing the same physical switching infrastructure.

Why the other options are wrong

  • A. NAT translates IP addresses, primarily to conserve public IP addresses or hide internal network structure, not for internal segmentation.
  • B. VPNs create secure tunnels over public networks, primarily for remote access or site-to-site connectivity, not for internal campus segmentation.
  • C. A DMZ is a buffer zone between an organization's internal network and an external network (e.g., the internet), typically hosting public-facing services.

Virtual Local Area Network (VLAN)

A logical grouping of network devices that allows a network administrator to segment a single physical network into multiple separate broadcast domains.

  • Segments networks logically, not physically.
  • Enhances security and network performance.
  • Uses tagging (e.g., 802.1Q) to identify VLAN traffic.

Memory trick: VLANs carve up networks, VPNs tunnel through them.

More Communication and Network Security questions