AP Cybersecurity Unit 3 Lesson 4 Exercise 1

Unit 3 • 3.4 • Exercise 1

Exercise 1 — Network Segmentation Analysis

6 questions — Evaluate VLAN designs and segmentation policies

Score: 0 / 0 Predict the answer before selecting an option
Client Organization
Sycamore School District

Sycamore School District serves 5,000 students across 8 schools. The district network includes student Chromebook traffic, teacher workstations with access to the student information system (SIS), administrative offices handling payroll, a guest Wi-Fi network for visitors, and IoT devices (security cameras, HVAC controllers). All traffic currently flows through a single flat network with no segmentation.

Q1 Flat Network Risk
Sycamore’s entire district operates on a single flat network (10.0.0.0/16) with no VLANs. A student connects a personal device to a classroom Ethernet port and runs a network scanner. Which of the following systems could the student’s device potentially discover and attempt to access?
Q2 VLAN Purpose
The IT director proposes creating five VLANs: Student (VLAN 10), Teacher (VLAN 20), Admin (VLAN 30), Guest (VLAN 40), and IoT (VLAN 50). Which of the following BEST describes the primary security benefit of this design?
Q3 Inter-VLAN Routing
After deploying VLANs, teachers on VLAN 20 need to access the SIS server on the Admin VLAN 30. Students on VLAN 10 must be blocked from the SIS entirely. Which of the following configurations achieves this?
Q4 VLAN Hopping
A security auditor discovers that several switch ports in Sycamore classrooms are configured as trunk ports (carrying traffic for all VLANs) instead of access ports (assigned to a single VLAN). Which attack does this misconfiguration enable?
Q5 IoT Segmentation
Sycamore’s 200 security cameras are placed on IoT VLAN 50 with a firewall rule allowing only outbound traffic to the camera management server (10.30.1.5) on port 554. A camera is compromised through a firmware vulnerability. Which of the following attacks is MOST effectively contained by this segmentation?
Q6 Defense in Depth
Which of the following is NOT a valid reason for placing the guest Wi-Fi on a separate VLAN from the student network?
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 3 • 3.4 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]