CompTIA CySA+ (CS0-003)Security OperationsMedium

A cloud security architect wants to prevent lateral movement between application workloads that reside on the same subnet by enforcing granular, workload-level firewall policies instead of relying solely on VLAN boundaries. Which architectural concept BEST describes this approach?

  1. AAir-gapped network
  2. BNetwork address translation (NAT)
  3. CDemilitarized zone (DMZ)
  4. DMicrosegmentation
Show answer & explanation

Correct answer: D. Microsegmentation

Microsegmentation applies fine-grained, identity- or workload-based security policies down to the individual host or application level, restricting east-west traffic even within the same subnet or VLAN. A DMZ isolates public-facing services from the internal network, an air gap physically isolates a network entirely, and NAT translates addresses rather than enforcing segmentation policy.

Why the other options are wrong

  • A. Air-gapping means complete physical isolation, not granular in-network policy.
  • B. NAT translates IP addresses and does not enforce security policy between workloads.
  • C. A DMZ separates external-facing servers from the internal LAN, not workload-to-workload policy.

Microsegmentation

A security architecture technique that isolates individual workloads or applications with granular policies to limit lateral movement, even within the same network segment.

  • Goes beyond VLAN/subnet-level isolation
  • Commonly implemented via software-defined networking (SDN)
  • Reduces blast radius of a compromised workload

Memory trick: Micro means each workload gets its own tiny fence.

More Security Operations questions