Communication and Network SecurityMedium

CISSP Practice Question: A mid-size retailer recently consolidated network controls and stopped enforcing segmentation between…

Published July 28, 2026 · Free daily CISSP practice question
A mid-size retailer recently consolidated network controls and stopped enforcing segmentation between payment processing systems and the general corporate network. If the organization continues to neglect its network segmentation strategy, which outcome is MOST likely?
  1. A.Increased risk of attacker lateral movement and an expanded breach blast radius
  2. B.Improved cross-department data sharing and collaboration due to fewer boundaries
  3. C.Simplified network policy administration and reduced operational overhead
  4. D.Temporary performance gains from fewer access enforcement points
Correct answer: A. Increased risk of attacker lateral movement and an expanded breach blast radius

Correct Answer: A. Increased risk of attacker lateral movement and an expanded breach blast radius

Explanation (CISSP Manager Logic):

Network segmentation is a critical architectural control that enforces containment and the principle of least privilege. Removing these boundaries eliminates the organization's ability to isolate threats, allowing a minor compromise to escalate into a catastrophic enterprise-wide breach.

By maintaining network segmentation, you:

  • Limit the blast radius of security incidents to a single zone.
  • Ensure compliance with regulatory mandates like PCI DSS.
  • Improve detection capabilities by monitoring inter-zone traffic.

While the other options are relevant, they fall short because:

  • B: Prioritizing data sharing over security controls introduces unacceptable risk to sensitive payment assets.
  • C: Reduced administrative overhead is an operational convenience that does not justify the loss of risk mitigation.
  • D: Minor performance gains are negligible compared to the high cost of a potential data breach.

Think like a manager:

Security architecture must prioritize risk containment over operational ease. Managers must view segmentation as a strategic defense-in-depth requirement to protect the organization's most valuable assets.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions