Which device segments a network into zones with distinct security policies?
Choose an answer
Tap an option to check your answer.
Correct answer: firewall.
Why this is the answer
A firewall segments a network into zones, such as a demilitarized zone (DMZ), internal network, and external network, and enforces distinct security policies between these zones. It inspects incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. An IPS (Intrusion Prevention System) primarily detects and prevents known threats within a network, but doesn't inherently segment it into policy zones. A switch operates at Layer 2 and forwards frames based on MAC addresses, segmenting broadcast domains but not enforcing security policies between logical zones. An access point provides wireless connectivity and extends a network, but does not segment it for security policy enforcement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed