nerdexam
Isaca

CISA · Question #501

Which of the following recommendations by an IS auditor is the BEST control to protect an organization's corporate network from the guest wireless network?

The correct answer is C. Place the guest network in its own virtual local area network (VLAN).. Placing the guest network in its own VLAN (C) is the best control because it creates a logical network boundary that isolates guest traffic from the corporate network entirely - even if a guest device is compromised, it cannot directly reach internal corporate resources. Why the

Submitted by mateo_ar· Apr 18, 2026Protection of Information Assets

Question

Which of the following recommendations by an IS auditor is the BEST control to protect an organization's corporate network from the guest wireless network?

Options

  • AAuthenticate devices connecting to the guest network.
  • BEnsure the guest access point is running the latest software.
  • CPlace the guest network in its own virtual local area network (VLAN).
  • DHide the service set identifier (SSID) of the guest network.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    74% (25)
  • D
    18% (6)

Explanation

Placing the guest network in its own VLAN (C) is the best control because it creates a logical network boundary that isolates guest traffic from the corporate network entirely - even if a guest device is compromised, it cannot directly reach internal corporate resources.

Why the distractors fall short:

  • A (Authenticate guest devices): Authentication verifies identity but does nothing to prevent an authenticated guest from accessing corporate network segments - it doesn't create separation.
  • B (Latest software on AP): Patching reduces vulnerabilities on the access point itself but doesn't architecturally separate the two networks; a compromised AP could still bridge traffic.
  • D (Hide the SSID): Security through obscurity - the SSID is trivially discoverable with any wireless scanner and provides zero actual network isolation.

Memory tip: Think "separation of concerns" - the question asks about protecting the corporate network from the guest network, which requires network segmentation, not just authentication or hardening. VLAN = wall; the other options are locks on a door in a wall that doesn't exist yet.

Topics

#Network Security#VLAN#Network Segmentation#Wireless Security

Community Discussion

No community discussion yet for this question.

Full CISA Practice