nerdexam
Cisco

200-201 · Question #400

Which description is a defense-in-depth principal strategy?

The correct answer is B. implementing VLANs to segment network traffic. Implementing VLANs to segment network traffic is a defense-in-depth strategy that creates multiple layers of security by logically separating network segments, restricting lateral movement and containing potential breaches.

Submitted by rania.sa· Mar 6, 2026Security Concepts

Question

Which description is a defense-in-depth principal strategy?

Options

  • Aisolating employees with access to critical data
  • Bimplementing VLANs to segment network traffic
  • Cdeveloping approval flow for new hires
  • Ddesigning Active Directory groups

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    90% (18)
  • D
    5% (1)

Why each option

Implementing VLANs to segment network traffic is a defense-in-depth strategy that creates multiple layers of security by logically separating network segments, restricting lateral movement and containing potential breaches.

Aisolating employees with access to critical data

While a form of control, isolating employees is not a primary 'defense-in-depth' technical network or system strategy, but rather an administrative or physical control measure.

Bimplementing VLANs to segment network trafficCorrect

Implementing VLANs (Virtual Local Area Networks) to segment network traffic is a classic defense-in-depth strategy. It creates logical boundaries within a physical network, preventing unauthorized access between different segments and limiting the blast radius of a successful breach, thereby adding a layer of protection.

Cdeveloping approval flow for new hires

Developing an approval flow for new hires is an administrative security control related to onboarding and access management, not a technical defense-in-depth strategy.

Ddesigning Active Directory groups

Designing Active Directory groups is an administrative task for managing permissions and roles, which supports security but is not a standalone defense-in-depth strategy itself.

Concept tested: Defense-in-depth strategies (network segmentation)

Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-network-segmentation

Topics

#Defense-in-depth#Network segmentation#VLANs#Network security

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice