CompTIA Security+ (SY0-701)General Security ConceptsMedium
A security architect redesigns an internal corporate network so that even devices already inside the perimeter firewall must separately authenticate and be authorized before communicating with servers in a different internal zone, effectively isolating each zone from the others. Which zero trust concept does this design implement?
- APolicy Decision Point
- BMicrosegmentation
- CDemilitarized zone
- DVirtual private network
Show answer & explanationAnswer & explanation
Correct answer: B. Microsegmentation
Microsegmentation divides a network into small, isolated zones and enforces separate authentication and authorization for traffic moving between them, eliminating implicit trust based solely on network location. A VPN secures remote connections, a DMZ separates external-facing hosts, and a PDP is a logical decision-making component rather than a network segmentation technique.
Why the other options are wrong
- A. The PDP evaluates policy but does not itself describe the segmented network architecture.
- C. A DMZ separates public-facing servers from the internal network, not internal-to-internal segmentation.
- D. A VPN secures traffic over untrusted networks, not internal zone isolation.
Microsegmentation
A zero trust technique that divides a network into small, isolated segments, each requiring independent authentication and authorization for traffic between them.
- Eliminates implicit trust based on network location.
- Limits lateral movement if a segment is compromised.
- Often enforced via software-defined networking or host-based firewalls.
Memory trick: Trust nothing, verify every segment separately