350-201 exam dumps

350-201 practice question 79 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 79

Select 3

A company’s network has recently experienced a ransomware attack that spread laterally from one compromised device to several critical servers. To prevent similar incidents in the future, the IT team decides to implement network segmentation. Which of the following actions should the IT team take to achieve effective segmentation?

  1. A

    Create VLANs to separate devices based on their roles and enforce inter-VLAN traffic policies.

  2. B

    Deploy a single flat subnet for the entire network to simplify traffic monitoring.

  3. C

    Implement ACLs (Access Control Lists) on network devices to restrict communication between segments.

  4. D

    Use firewalls or next-generation firewalls to inspect traffic between network segments.

  5. E

    Disable VLAN tagging to ensure traffic flows freely between all devices.

Show answer and explanation

Correct answers: A, C, D

Explanation

Network segmentation involves dividing a network into smaller, isolated segments to limit lateral movement of threats and enforce access control. VLANs, ACLs, and firewalls are key tools for implementing segmentation. A flat subnet or disabling VLAN tagging would undermine security by allowing unrestricted communication across the network.

  • A. Correct.

    Correct: Creating VLANs separates devices into logical groups based on their roles, such as separating servers, workstations, and IoT devices. This reduces the risk of lateral movement during an attack.

  • B. Incorrect.

    Incorrect: A flat subnet would allow all devices to communicate freely without any restrictions. This increases the risk of lateral movement and is contrary to the principle of segmentation.

  • C. Correct.

    Correct: ACLs provide fine-grained control over which devices or users can communicate with each other, enforcing the segmentation policy.

  • D. Correct.

    Correct: Firewalls or next-generation firewalls can inspect and enforce policies for traffic moving between segments, offering additional security and visibility.

  • E. Incorrect.

    Incorrect: Disabling VLAN tagging removes the logical separation between devices, effectively nullifying segmentation and increasing vulnerability to attacks.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam