Finance servers and guest Wi-Fi clients currently share one flat VLAN in city hall. What logical segmentation approach should the architect apply?
Select an answer to reveal the explanation.
Short Explanation
Guests and finance on one flat VLAN is a mixer party for malware. Carve separate VLANs—and tighter routing constructs when needed—so visitors cannot stroll into payroll.
Full Explanation
Logical segmentation using VLANs, VPNs, and virtual routing constructs (such as VRF) separates trust zones without requiring fully distinct physical plants. Finance and guest Wi-Fi must not share a flat broadcast/security domain. Proper logical segmentation limits lateral movement and enforces policy boundaries.