The network team offers to place the appliance's management interface on the backup-data VLAN because 'the port is already there'. What is the correct design response?
Select an answer to reveal the explanation.
Short Explanation
Cramming management onto the backup-data VLAN is like doing your paperwork in the loading dock while the forklifts run. When the backup traffic floods that pipe, the GUI, the monitoring polls, and your alerts are what drown — and you've widened the crowd that can reach admin too. Keep management on its own plane; 'a port happens to be there' is not a design.
Full Explanation
Separating management from data planes is a design rule with two independent roots, both operational. First, management interfaces must remain responsive while data interfaces absorb full-bandwidth bursts: co-locating them on one congested broadcast domain means the GUI, monitoring polls, and alert traffic queue behind backup streams precisely when an emergency makes them most needed. Second, administrative access is permitted from a narrow population; placing the management endpoint on the data VLAN widens that permitted population to every host the data plane reaches, quietly unwinding the estate's own segmentation. The jumbo-inheritance argument fails twice over: ordinary management flows gain nothing from large frames, and the VLAN engineered for bulk backup traffic is exactly the network management should not share. The two-ports claim is false by hardware fact — these appliances provide multiple interfaces precisely so management and data roles can be separated physically as well as logically. Moving management onto the replication VLAN repeats the same category error somewhere else, since replication is another high-volume, single-purpose plane with its own tuning. Exam caveat: physical interface separation alongside VLAN separation is good practice where the design allows it, but plane separation is the principle the exam tests. Operational check: confirm the management interface sits on the admin VLAN, verify it is reachable only from the admin subnet's permitted sources, and document each interface's role.