CompTIA CySA+ (CS0-003)Security OperationsMedium
A cloud security architect wants to prevent lateral movement between application workloads that reside on the same subnet by enforcing granular, workload-level firewall policies instead of relying solely on VLAN boundaries. Which architectural concept BEST describes this approach?
- AAir-gapped network
- BNetwork address translation (NAT)
- CDemilitarized zone (DMZ)
- DMicrosegmentation
Show answer & explanationAnswer & explanation
Correct answer: D. Microsegmentation
Microsegmentation applies fine-grained, identity- or workload-based security policies down to the individual host or application level, restricting east-west traffic even within the same subnet or VLAN. A DMZ isolates public-facing services from the internal network, an air gap physically isolates a network entirely, and NAT translates addresses rather than enforcing segmentation policy.
Why the other options are wrong
- A. Air-gapping means complete physical isolation, not granular in-network policy.
- B. NAT translates IP addresses and does not enforce security policy between workloads.
- C. A DMZ separates external-facing servers from the internal LAN, not workload-to-workload policy.
Microsegmentation
A security architecture technique that isolates individual workloads or applications with granular policies to limit lateral movement, even within the same network segment.
- Goes beyond VLAN/subnet-level isolation
- Commonly implemented via software-defined networking (SDN)
- Reduces blast radius of a compromised workload
Memory trick: Micro means each workload gets its own tiny fence.