A city WLAN carries employee laptops, guest tablets, and building IoT sensors on the same SSID and VLAN today. Which segmentation approach best aligns with layered WLAN-supporting security?
Select an answer to reveal the explanation.
Short Explanation
Staff, guests, and thirsty IoT sensors shouldn’t share one swimming pool. Separate VLANs (and usually SSIDs or dynamic assignment) give each group its own lane so a compromised lightbulb doesn’t get a free paddle to HR file shares.
Full Explanation
Network segmentation with separate VLANs for staff, guest, and IoT populations is a core layered-security practice supporting WLANs. A shared flat VLAN with only PSK rotation, intentional co-location to hide traffic from firewalls, or partial isolation that still mixes staff and guests on production VLANs fails to enforce distinct trust boundaries. Pairing VLAN separation with SSID or dynamic VLAN assignment keeps civic user classes from sharing one Layer-2 blast radius.