nerdexam
Cisco

300-710 · Question #95

An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks. What must be configured in order to maintain data privacy for both d

The correct answer is B. Use 802.1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation. To maintain data privacy between the sales and product development departments, which are on two separate networks, the key requirement is to ensure logical traffic separation so that data from one department cannot be accessed or intercepted by the other. The best approach is to

Configuration

Question

An engineer is monitoring network traffic from their sales and product development departments, which are on two separate networks. What must be configured in order to maintain data privacy for both departments?

Options

  • AUse a dedicated IPS inline set for each department to maintain traffic separation
  • BUse 802.1Q mime set Trunk interfaces with VLANs to maintain logical traffic separation
  • CUse passive IDS ports for both departments
  • DUse one pair of inline set in TAP mode for both departments

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    91% (51)
  • C
    5% (3)
  • D
    2% (1)

Explanation

To maintain data privacy between the sales and product development departments, which are on two separate networks, the key requirement is to ensure logical traffic separation so that data from one department cannot be accessed or intercepted by the other. The best approach is to use VLANs with 802.1Q trunking to maintain logical traffic separation. VLANs (Virtual Local Area Networks) allow network administrators to segment the network logically by department or function, isolating traffic within each VLAN and preventing unauthorized access between them. This segmentation improves security by containing any potential breaches within a VLAN and ensuring sensitive data remains accessible only to authorized users within that VLAN. The 802.1Q standard enables VLAN tagging, which inserts a VLAN identifier into Ethernet frames, allowing multiple VLANs to share the same physical network infrastructure (trunk links) without mixing traffic. This tagging ensures that traffic from sales and product development departments remains separate even though it may traverse the same physical switches.

Topics

#VLANs#802.1Q Trunking#Network Segmentation#Data Privacy

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice