SY0-701 exam dumps

SY0-701 practice question 161 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 161

Single answerNetwork infrastructure

A company is expanding its office and needs to connect a third-party HVAC management system to the corporate network so facilities staff can monitor building controls remotely. The HVAC vendor requires IP connectivity to a cloud portal, but the security team is concerned about exposing internal systems if the vendor device is compromised. The company wants the HVAC system to have only the network access it needs while minimizing risk to user workstations and servers. Which of the following is the BEST solution?

  1. A

    Place the HVAC controller on the same internal VLAN as the facilities staff workstations and use host-based firewalls on the PCs

  2. B

    Connect the HVAC controller to a screened subnet/isolated VLAN and restrict traffic with ACLs or firewall rules to only required destinations and ports

  3. C

    Allow the HVAC controller on the corporate LAN, but enable port security on the switch to limit the number of MAC addresses on the port

  4. D

    Install the HVAC controller on the guest wireless network so it is separated from the corporate LAN, even if staff must use the internet to manage it

Show answer and explanation

Correct answer: B

Explanation

The best answer is to place the third-party HVAC system in an isolated network segment and strictly control traffic to and from it. Security+ emphasizes network segmentation, VLANs, screened subnets, and least-privilege access as effective ways to reduce attack surface and limit lateral movement. This is especially important for IoT, operational technology, and vendor-managed devices, which often require connectivity but should not be trusted at the same level as internal corporate assets. In practice, organizations commonly place such systems in dedicated VLANs or DMZ-like segments and apply ACLs, firewall policies, and egress restrictions so only necessary protocols, ports, and destinations are allowed. This aligns with common security guidance from NIST, including principles in NIST SP 800-41 for firewall policy and NIST SP 800-125/800-82 concepts around segmentation and isolation of specialized or industrial systems.

  • A. Incorrect.

    This is incorrect because placing the HVAC controller on the same internal VLAN as facilities workstations does not provide sufficient network segmentation. Host-based firewalls on user systems help protect those individual endpoints, but they do not adequately isolate the third-party device from the rest of the internal network. If the HVAC controller were compromised, an attacker could still attempt lateral movement within that VLAN.

  • B. Correct.

    This is correct because isolating the HVAC controller in a screened subnet or dedicated VLAN and enforcing least-privilege communication with ACLs or firewall rules is a standard network infrastructure security practice. This approach limits east-west movement, reduces exposure of internal assets, and permits only the specific outbound or management traffic required for the HVAC function. It is a practical implementation of segmentation for untrusted or third-party-managed systems.

  • C. Incorrect.

    This is incorrect because port security addresses a different problem: limiting which MAC addresses can connect to a switch port. While useful for preventing unauthorized devices from being plugged in, it does not meaningfully restrict the HVAC controller's ability to communicate broadly once connected. It is not a substitute for segmentation or traffic filtering.

  • D. Incorrect.

    This is incorrect because a guest wireless network is typically designed for transient internet-only user access, not for operational technology or building management systems that may require controlled administrative access and reliability. Although it provides some separation, it is usually not the best architecture for a business-critical infrastructure device. It can also complicate secure management and may not provide the granular traffic controls available with a dedicated VLAN or screened subnet.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam