Question 1 of 30
In a corporate network, a security analyst is tasked with implementing segmentation to enhance security and reduce the attack surface. The network consists of multiple departments, including HR, Finance, and IT, each with different security requirements and access controls. The analyst decides to use VLANs (Virtual Local Area Networks) to segment the network. Given that the HR department requires access to sensitive employee data, the Finance department needs to access financial records, and the IT department requires access to all systems for maintenance, which of the following segmentation strategies would best minimize the risk of unauthorized access while ensuring necessary access for each department?
Create separate VLANs for HR, Finance, and IT, applying strict ACLs (Access Control Lists) to control inter-VLAN traffic based on the principle of least privilege.
Use a single VLAN for all departments to simplify management and reduce overhead, relying on strong passwords for access control.
Implement a flat network architecture where all devices are on the same subnet, allowing for easier communication between departments without restrictions.
Create a single VLAN for HR and Finance while allowing IT to access both, thus simplifying the network structure and reducing complexity.

Preparing for CISCO 200-201 Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free