CV0-003 · Question #259
Which of the following would allow separation between the Internet and the internal network of a company?
The correct answer is A. Virtual Local Area Networks. VLANs logically segment a network at Layer 2, allowing an organization to isolate Internet-facing traffic from internal network traffic using a single physical infrastructure.
Question
Which of the following would allow separation between the Internet and the internal network of a company?
Options
- AVirtual Local Area Networks
- BReview Audit Logs
- CReview System Logs
- DDemilitarized zone
How the community answered
(41 responses)- A90% (37)
- B2% (1)
- C5% (2)
- D2% (1)
Why each option
VLANs logically segment a network at Layer 2, allowing an organization to isolate Internet-facing traffic from internal network traffic using a single physical infrastructure.
Virtual Local Area Networks (VLANs) create separate broadcast domains at Layer 2, enabling administrators to assign Internet-facing and internal devices to distinct logical segments. Access between VLANs can then be tightly controlled through ACLs or firewall policies applied at the Layer 3 boundary, enforcing separation between external and internal traffic without requiring fully separate physical hardware.
Reviewing audit logs is a detective control that records events after they occur and provides no technical barrier or network separation between the Internet and internal systems.
Reviewing system logs offers visibility into system activity but creates no network-level boundary and cannot enforce separation between Internet and internal traffic.
A DMZ describes a network zone architecture placed between two firewalls, but it is the result of a design decision rather than the specific mechanism (such as a VLAN) that enforces the logical separation itself.
Concept tested: VLAN-based network segmentation for perimeter isolation
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/vlans.html
Topics
Community Discussion
No community discussion yet for this question.