nerdexam
CompTIA

SY0-501 · Question #70

A security engineer is faced with competing requirements from the networking group and database administrators. The database administrators would like ten application servers on the same subnet for…

The correct answer is B. Recommend classifying each application into like security groups and segmenting the groups. When competing requirements exist between network segmentation and administrative convenience, security administrators should classify applications by security group and segment accordingly, balancing both security and operational needs.

Submitted by haruto_sh· Mar 4, 2026Security architecture

Question

A security engineer is faced with competing requirements from the networking group and database administrators. The database administrators would like ten application servers on the same subnet for ease of administration, whereas the networking group would like to segment all applications from one another. Which of the following should the security administrator do to rectify this issue?

Options

  • ARecommend performing a security assessment on each application, and only segment the
  • BRecommend classifying each application into like security groups and segmenting the groups
  • CRecommend segmenting each application, as it is the most secure approach
  • DRecommend that only applications with minimal security features should be segmented to

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    84% (37)
  • C
    5% (2)
  • D
    2% (1)

Why each option

When competing requirements exist between network segmentation and administrative convenience, security administrators should classify applications by security group and segment accordingly, balancing both security and operational needs.

ARecommend performing a security assessment on each application, and only segment the

Segmenting only applications that fail a security assessment is reactive rather than proactive and ignores the principle that all applications should be evaluated for placement within a security architecture regardless of individual vulnerabilities.

BRecommend classifying each application into like security groups and segmenting the groupsCorrect

Classifying applications into like security groups and segmenting those groups represents a risk-based, balanced approach that satisfies both teams - it provides meaningful network segmentation to reduce lateral movement risk while grouping similar applications together for administrative efficiency. This approach aligns with the principle of security zoning, where assets with similar sensitivity, trust levels, and functions share a segment, reducing attack surface without creating unmanageable complexity. It is a practical compromise rooted in security best practices rather than an all-or-nothing solution.

CRecommend segmenting each application, as it is the most secure approach

While segmenting every application individually is the most secure theoretical approach, it completely disregards the database administrators' legitimate operational requirements and fails to balance competing business needs, which is a core responsibility of a security administrator.

DRecommend that only applications with minimal security features should be segmented to

Segmenting only applications with minimal security features inverts sound security logic - applications with fewer built-in security controls are higher risk and may warrant segmentation, but this criterion alone is insufficient and inconsistent as a segmentation policy.

Concept tested: Network segmentation using security group classification

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/network-best-practices

Topics

#network segmentation#security architecture#risk-based classification#application isolation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice