nerdexam
Cisco

200-201 · Question #385

A company plans to implement network segmentations and use IP address inventory management best practices. Servers and end-user devices are using the same VLANs and IP subnets with manual address assi

The correct answer is D. Assign separate hard-coded IP address spaces for critical assets, according to their role and E. Create IP address inventory database and deploy separate role-based IP subnetting for users. To implement network segmentation and improve IP management, engineers must first establish an IP inventory and then create separate, role-based IP subnetting for critical assets and users.

Submitted by naveen.iyer· Mar 6, 2026Security Policies and Procedures

Question

A company plans to implement network segmentations and use IP address inventory management best practices. Servers and end-user devices are using the same VLANs and IP subnets with manual address assignment. What are the first two steps the engineers must take to meet these requirements? (Choose two.)

Options

  • AConfigure packet captures to perform deep packet inspection for further traffic analysis and
  • BImplement deep network traffic analysis using NetFlow v5 from routers and switches.
  • CDeploy an Active Directory server and add all assets to the created domain for better visibility.
  • DAssign separate hard-coded IP address spaces for critical assets, according to their role and
  • ECreate IP address inventory database and deploy separate role-based IP subnetting for users

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    15% (6)
  • C
    10% (4)
  • D
    70% (28)

Why each option

To implement network segmentation and improve IP management, engineers must first establish an IP inventory and then create separate, role-based IP subnetting for critical assets and users.

AConfigure packet captures to perform deep packet inspection for further traffic analysis and

Configuring packet captures and deep packet inspection is for traffic analysis and troubleshooting, not a first step for implementing network segmentation or IP address management.

BImplement deep network traffic analysis using NetFlow v5 from routers and switches.

Implementing deep network traffic analysis using NetFlow is for monitoring and understanding traffic patterns, which comes after segmentation is designed and implemented, not as a first step to achieve it.

CDeploy an Active Directory server and add all assets to the created domain for better visibility.

Deploying an Active Directory server and adding assets for better visibility is related to identity management and centralized authentication, which is not a direct first step for network segmentation or IP address inventory as described.

DAssign separate hard-coded IP address spaces for critical assets, according to their role andCorrect

Assigning separate hard-coded IP address spaces for critical assets, based on their role and function, is a fundamental step towards network segmentation. This isolates sensitive systems, making it easier to apply specific security policies and control traffic flow to and from these critical resources, moving away from a flat network structure.

ECreate IP address inventory database and deploy separate role-based IP subnetting for usersCorrect

Creating an IP address inventory database is essential for managing and tracking IP assignments and for identifying all assets on the network. Deploying separate role-based IP subnetting for users and devices, aligned with new VLANs, directly supports network segmentation best practices by logically separating different types of network traffic and devices.

Concept tested: Network segmentation and IP management

Source: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/ip-addressing

Topics

#Network segmentation#IP address management#VLANs#Network security best practices

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice