nerdexam
Cisco

350-201(NEW-127Q) · Question #105

An organization has four quiet rooms and two meeting rooms. A security engineer must enhance network protection by separating employee access to internal resources and visitor access to only the…

The correct answer is C. VLANs. VLANs (Virtual Local Area Networks) are the right choice because they logically segment a single physical network into isolated broadcast domains - perfect for separating employee traffic (internal resources) from visitor traffic (internet-only) across the quiet and meeting…

Network Security

Question

An organization has four quiet rooms and two meeting rooms. A security engineer must enhance network protection by separating employee access to internal resources and visitor access to only the internet. Which type of segmentation should a security engineer recommend?

Options

  • AIPsec
  • BDMZ
  • CVLANs
  • DVPN

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    9% (4)
  • C
    71% (32)
  • D
    16% (7)

Explanation

VLANs (Virtual Local Area Networks) are the right choice because they logically segment a single physical network into isolated broadcast domains - perfect for separating employee traffic (internal resources) from visitor traffic (internet-only) across the quiet and meeting rooms without needing separate physical infrastructure.

Why the distractors are wrong:

  • A. IPsec - A tunneling/encryption protocol used to secure traffic in transit (often in VPNs); it doesn't segment network access by user group.
  • B. DMZ - A DMZ creates a buffer zone between the internet and an internal network for hosting public-facing servers (web, email), not for separating employee vs. visitor access within a building.
  • D. VPN - A VPN creates an encrypted tunnel for remote users to reach internal resources securely; it doesn't address on-site segmentation between different types of users.

Memory tip: Think "VLAN = Virtual Lanes" - like highway lanes that keep different types of traffic separated on the same road. When the question involves who can access what on the same physical network, VLANs are almost always the answer.

Topics

#VLANs#Network Segmentation#Access Control#Network Architecture

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice