CompTIA Security+ (SY0-701)Security ArchitectureMedium

A security architect is redesigning a data center network so that if an attacker compromises one virtual machine, they cannot easily move laterally to other VMs in the same subnet, even though those VMs previously trusted each other. Which approach BEST achieves this goal?

  1. AEnabling port security on access switches
  2. BImplementing microsegmentation with per-workload policies
  3. CIncreasing the subnet size to reduce broadcast traffic
  4. DDeploying a single perimeter firewall at the network edge
Show answer & explanation

Correct answer: B. Implementing microsegmentation with per-workload policies

Microsegmentation applies granular, workload-level security policies (often via SDN or hypervisor-level controls) to control east-west traffic between hosts, preventing lateral movement even within the same subnet.

Why the other options are wrong

  • A. Port security prevents MAC spoofing on a switch port, not lateral movement between VMs.
  • C. Larger subnets increase, not reduce, the lateral movement attack surface.
  • D. A perimeter firewall only inspects north-south traffic entering/leaving the network, not internal east-west traffic.

Microsegmentation

A security technique that enforces granular access policies between individual workloads or VMs, restricting east-west (lateral) traffic even within the same network segment.

  • Limits lateral movement after a breach
  • Often implemented via SDN or hypervisor-based firewalls
  • Core component of zero trust architectures

Memory trick: Wall off every workload, not just the border.

More Security Architecture questions