Which Technique Separates Customer Data from the Corporate Network?

An organization would like to store customer data on a separate part of the network that is not accessible to users on the main corporate network. Which of the following should the administrator use to accomplish this goal?

  1. Segmentation Source Reference Answer
  2. Isolation
  3. Patching
  4. Encryption

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to distinguish between logical traffic division (segmentation) and total disconnection (isolation), with the primary trap being the selection of isolation due to its stronger security connotation.

This question evaluates the practical application of network architecture controls to protect sensitive data. The community overwhelmingly agrees that logical network division via segmentation is the correct solution, distinguishing it from complete environmental separation.

Candidates frequently select Isolation because they equate "not accessible" with complete separation. However, isolation implies an air-gapped or fully disconnected environment, whereas the prompt specifies storing data on a "separate part of the network," making segmentation the precise architectural match.

Community Discussion (10 comments)

MAKOhunter33333333 👍 14 Selected: A
Mentions the org wants to store it on the network just separate from the main network, which is segmentation.
AutoroTink 👍 7
Further notes: Isolation is a security measure that can be used to protect sensitive data which typically involves creating a completely separate environment, such as a different physical server or a standalone network, which can be more restrictive than segmentation. The question has the data still on the network, just in a separate part. So, Option A is still the best answer.
famuza77 👍 1 Selected: B
it is Isolation
dbrowndiver 👍 3 Selected: A
Segmentation is the correct answer because it involves creating distinct network segments that control access and separate sensitive customer data from the main corporate network. Network segmentation is the most appropriate solution for ensuring that customer data is stored securely and not accessible to unauthorized users.
drosas84 👍 5 Selected: A
Network segmentation involves dividing a network into subnets to control access and traffic flow. Network isolation is more severe, creating a standalone network with no connectivity to other parts of the network. It's a stringent form of segregation.
hasquaati 👍 2 Selected: A
Answer is A. While Isolation is a legitimate answer, that design is more relevant to machinery and manufacturing equipment.
AutoroTink 👍 1 Selected: A
While isolation is a broader concept that can include segmentation, it typically refers to completely separating a system or environment from others, which might be more extreme than necessary for this purpose. Segmentation can help in isolating the customer data from the main corporate network, ensuring that it is not accessible to unauthorized users
Yoez 👍 1 Selected: B
The correct answer is: B. Isolation Isolation involves creating separate network segments or zones that restrict access between them. By isolating the network segment where customer data is stored from the main corporate network, the organization can prevent unauthorized users on the corporate network from accessing the sensitive customer data. This helps enhance security by limiting the potential attack surface and reducing the risk of unauthorized access or data breaches.
shady23 👍 1 Selected: A
A. Segmentation
3056f7e 👍 1
B cause A only involves dividing a network into smaller segments to improve security and performance but may still allow communication between segments.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Logical Network Division

The correct answer is A. Segmentation. Network segmentation involves dividing a larger physical network into multiple smaller, logical subnetworks (such as VLANs or subnets). This architecture enforces strict access controls between segments using firewalls, ACLs, and routing policies, ensuring that users on the main corporate network cannot directly access systems hosting sensitive customer data. As highlighted by top-voted community members, segmentation provides the necessary security boundary while maintaining operational connectivity where required.

Differentiating Segmentation from Isolation

Many candidates mistakenly choose B. Isolation, often due to its association with maximum security. However, in networking terminology, isolation typically refers to creating a completely standalone environment with zero network connectivity to other systems (e.g., an air-gapped server or physically disconnected hardware). Community experts clarify that since the prompt explicitly states the data will be on a "separate part of the network," complete disconnection is unnecessary and technically inaccurate. Segmentation achieves the goal of restricting access through logical boundaries without severing the network link entirely.

Why Patching and Encryption Don't Fit

C. Patching focuses on updating software and firmware to remediate vulnerabilities; it does not restrict network access or divide infrastructure. D. Encryption protects data confidentiality at rest or in transit by scrambling information, but it does not inherently prevent unauthorized network-level access or isolate network segments. While encryption is a critical complementary control, it does not solve the architectural requirement described in the scenario.

Exam Takeaway

When a CompTIA Security+ question describes dividing a network into zones or subnets to limit lateral movement and control traffic flow, always prioritize segmentation. Reserve isolation for scenarios emphasizing complete disconnection, air gaps, or sandboxed environments.

Official Reference

  • CompTIA Security+ SY0-701 Exam Objectives: Domain 4.1 - Implement and manage basic network security components
  • NIST Special Publication 800-47 Rev. 1: Breaking Down Security Barriers Within and Between Information Systems
  • Cisco Networking Academy: Introduction to Networks - Switch Virtual Internals (SVI) and Inter-VLAN Routing

Exam Strategy

Focus heavily on the exact wording in scenario-based questions: phrases like "separate part of the network" or "divide into subnets" point directly to segmentation, while "completely disconnected" or "no external connections" signal isolation. Always match the technical term to the level of restriction described in the prompt rather than defaulting to the "most secure" option.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide