Home MCQs CISA Question #6867
Back to Questions
CISA QUESTION #6867
Question 1
An organization's network architecture uses VLANs to segment traffic but all VLANs route through a single core switch with no filtering between VLANs. What is the PRIMARY security weakness?
  • Insufficient VLAN count
  • VLAN segmentation provides no security benefit without inter-VLAN filtering✔️
  • Complex routing
  • Single point of failure
Correct Answer Explanation
VLANs provide only logical separation—without filtering between VLANs (through firewalls or ACLs), they provide minimal security benefit. Traffic can move freely between VLANs, defeating segmentation's security purpose. Effective segmentation requires both logical separation and enforcement of access controls between segments.