Communication and Network SecurityEasy

CISSP Practice Question: In a mid-sized healthcare organization, which is MOST likely to happen if…

Published October 8, 2026 · Free daily CISSP practice question
In a mid-sized healthcare organization, which is MOST likely to happen if network segmentation is not implemented effectively?
  1. A.Increased risk of data breaches
  2. B.Improved network performance
  3. C.Lower operational costs
  4. D.Enhanced regulatory compliance
Correct answer: A. Increased risk of data breaches

Correct Answer: A. Increased risk of data breaches

Explanation (CISSP Manager Logic):

A flat network architecture lacks internal boundaries, allowing a single compromise to escalate into a full-scale breach through lateral movement. Effective segmentation reduces the "blast radius" by isolating sensitive patient data from general traffic and unauthorized users.

By implementing this solution, you:

  • Contain security incidents within isolated network zones.
  • Enforce the Principle of Least Privilege at the infrastructure level.
  • Reduce the organizational risk profile and audit scope.

While the other options are relevant, they fall short because:

  • B: Lack of segmentation often leads to broadcast storms and congestion, which degrades performance.
  • C: Inadequate security increases long-term costs through incident response, legal fees, and fines.
  • D: Regulatory mandates like HIPAA require strict data isolation, which is impossible without segmentation.

Think like a manager:

Prioritize risk containment and asset protection. Use segmentation as a strategic control to minimize the impact of a breach on business continuity and regulatory standing.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions