CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security team is implementing a Zero Trust architecture across a highly distributed cloud environment. They need to ensure that every request between services, regardless of its origin or destination within the environment, is explicitly authenticated and authorized. This includes requests within the same cloud region, across regions, and even across different cloud providers. Which of the following concepts is central to achieving this level of granular, per-request security?
- ANetwork Segmentation
- BMicro-segmentation
- CPerimeter-based Security
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: B. Micro-segmentation
Micro-segmentation is a security technique that creates secure zones in data centers and cloud environments, allowing organizations to isolate workloads from one another and secure them individually. In a Zero Trust model, this means applying security policies to individual workloads, down to the individual service or application, rather than relying on network perimeters.
Why the other options are wrong
- A. Network segmentation divides networks into larger segments, but not down to the granular, per-service level required by Zero Trust.
- C. Perimeter-based security is diametrically opposed to Zero Trust, relying on a strong outer boundary but trusting everything within.
- D. VPNs provide secure tunnels for network traffic but do not inherently provide granular, per-request authentication and authorization between services within a distributed cloud environment.
Micro-segmentation
A network security technique that creates secure zones to isolate individual workloads, applying granular security policies to each, rather than relying on broad network perimeters.
- Creates granular security zones
- Isolates individual workloads/services
- Enforces fine-grained policies
- Key component of Zero Trust
Memory trick: Micro-segmentation: Tiny walls for ultimate trust.