CompTIA Security+ (SY0-701)Security OperationsHard

A security architect is redesigning network access controls under a zero trust model. Instead of relying on a flat internal network where any authenticated device can reach any server, the architect wants to isolate each application workload so that lateral movement between systems requires explicit policy approval for every connection. Which approach BEST achieves this goal?

  1. AEnabling port security on all access-layer switches
  2. BDeploying a single perimeter firewall at the network edge
  3. CImplementing microsegmentation with policy enforcement between workloads
  4. DRequiring VPN access for all remote employees
Show answer & explanation

Correct answer: C. Implementing microsegmentation with policy enforcement between workloads

Microsegmentation divides the network into granular zones, often down to the individual workload level, and enforces explicit policy for every connection, directly aligning with zero trust's principle of never trusting implicit lateral access.

Why the other options are wrong

  • A. Port security restricts which MAC addresses connect to a switch port, not workload-to-workload policy.
  • B. A single perimeter firewall protects the edge but does not control internal lateral movement.
  • D. VPN access secures remote connectivity into the network, not internal lateral segmentation.

Microsegmentation

A zero trust network security technique that divides a network into small, isolated segments—often per workload—requiring explicit policy approval for any communication between them.

  • Core zero trust principle: never trust, always verify, even internally
  • Reduces blast radius by limiting lateral movement
  • Often implemented via software-defined networking or host-based firewalls

Memory trick: Wall off every room in the house so a burglar can't roam freely.

More Security Operations questions