CompTIA Security+ (SY0-701)General Security ConceptsMedium

A security architect redesigns an internal corporate network so that even devices already inside the perimeter firewall must separately authenticate and be authorized before communicating with servers in a different internal zone, effectively isolating each zone from the others. Which zero trust concept does this design implement?

  1. APolicy Decision Point
  2. BMicrosegmentation
  3. CDemilitarized zone
  4. DVirtual private network
Show answer & explanation

Correct answer: B. Microsegmentation

Microsegmentation divides a network into small, isolated zones and enforces separate authentication and authorization for traffic moving between them, eliminating implicit trust based solely on network location. A VPN secures remote connections, a DMZ separates external-facing hosts, and a PDP is a logical decision-making component rather than a network segmentation technique.

Why the other options are wrong

  • A. The PDP evaluates policy but does not itself describe the segmented network architecture.
  • C. A DMZ separates public-facing servers from the internal network, not internal-to-internal segmentation.
  • D. A VPN secures traffic over untrusted networks, not internal zone isolation.

Microsegmentation

A zero trust technique that divides a network into small, isolated segments, each requiring independent authentication and authorization for traffic between them.

  • Eliminates implicit trust based on network location.
  • Limits lateral movement if a segment is compromised.
  • Often enforced via software-defined networking or host-based firewalls.

Memory trick: Trust nothing, verify every segment separately

More General Security Concepts questions