SY0-701 exam dumps

SY0-701 practice question 165 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 165

Single answerLogical segmentation

A company is preparing for a security audit after discovering that employee workstations can directly communicate with payroll servers and building-management controllers on the same internal network. The security administrator needs to reduce the risk of lateral movement without purchasing new switching hardware. Which of the following should the administrator implement FIRST to provide logical separation between these systems while still using the existing physical network infrastructure?

  1. A

    Create VLANs for user devices, payroll systems, and building-management controllers, and control traffic between them with ACLs or firewall rules

  2. B

    Replace all Cat6 cabling with fiber to isolate traffic and reduce the chance of interception

  3. C

    Enable port security on access switches to limit the number of MAC addresses per port

  4. D

    Deploy full-disk encryption on payroll servers and building-management controllers

Show answer and explanation

Correct answer: A

Explanation

Logical segmentation is used to separate networks by function, sensitivity, or trust level without necessarily adding new physical infrastructure. In this scenario, the main issue is that flat internal connectivity allows employee workstations to directly reach sensitive systems, increasing the risk of lateral movement after compromise. The most appropriate first step is to create separate VLANs for different classes of systems and then enforce traffic restrictions between them using router ACLs, Layer 3 switch ACLs, or internal firewall policies. This aligns with common security architecture guidance such as network segmentation recommendations from NIST, including NIST SP 800-41 for firewalls and policy enforcement and zero trust-oriented guidance in NIST SP 800-207, which emphasizes limiting unnecessary communication paths. Port security and encryption are useful controls, but they do not solve the core problem of logical network separation.

  • A. Correct.

    Correct. VLANs are a standard method of logical segmentation that allow multiple security zones to share the same physical switching infrastructure while remaining separated at Layer 2. Applying ACLs or firewall rules between VLANs further restricts east-west traffic and helps prevent unauthorized communication and lateral movement. This directly addresses the scenario's requirement to improve separation without buying new hardware.

  • B. Incorrect.

    Incorrect. Fiber can improve distance and resistance to electromagnetic interference, and in some cases can reduce certain interception risks, but replacing cabling does not logically segment systems on the network. Devices would still be able to communicate unless segmentation controls such as VLANs, ACLs, or firewalls were implemented.

  • C. Incorrect.

    Incorrect. Port security helps control which devices can connect to a switch port by limiting or validating MAC addresses, but it does not create separate security zones for payroll, user, and building-management systems. A candidate might pick this because it is a switch-based security feature, but it is focused on endpoint attachment control, not logical segmentation.

  • D. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a device is stolen or improperly decommissioned. It does not prevent live network communication between user workstations and sensitive systems. This is a common misconception: encryption at rest improves confidentiality of stored data, but not network isolation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam