A financial services firm is redesigning its office network to enhance security. The Chief Information Security Officer (CISO) has mandated that the trading, research, and administrative departments, all of which use the same physical switching infrastructure, must be logically separated to prevent broadcast traffic from crossing departmental boundaries. This measure is intended to contain potential security incidents within a single department. Which of the following solutions would BEST achieve this Layer 2 isolation requirement?
Virtual Local Area Networks (VLANs) are the correct solution for this scenario because they are specifically designed to provide Layer 2 traffic isolation on a shared physical network infrastructure. By creating separate broadcast domains for each department (trading, research, administrative), VLANs ensure that traffic from one department does not cross over into another at Layer 2, effectively segmenting the network as required.
Network Address Translation (NAT) operates at Layer 3 and is used to translate IP addresses (typically private to public), but it does not provide Layer 2 traffic isolation between systems on the same internal network. Software-Defined Networking (SDN) is a network architecture approach that decouples the control and data planes; while it can be used to manage and configure segmentation policies like VLANs, SDN itself is the architectural approach, not the specific isolation technology. Port security is a switch feature that restricts access to a port based on MAC addresses but does not create broad, segment-wide isolation between groups of devices across multiple switch ports.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a VLAN and how does it achieve traffic isolation?
Open an interactive chat with Bash
How does VLAN traffic differ from regular Layer 2 broadcast traffic?
Open an interactive chat with Bash
What role do VLAN tags play in Layer 2 traffic management?
Open an interactive chat with Bash
ISC2 CISSP
Communication and Network Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .