CompTIA SecurityX (CAS-005)Security OperationsMedium

A security analyst is performing a post-incident review after a significant data breach. The root cause analysis indicates that the attackers gained initial access through a vulnerable web application, then escalated privileges, and finally moved laterally to a database server to exfiltrate data. To prevent similar future incidents, which of the following security controls would have been most effective in limiting the impact of the lateral movement phase?

  1. AStrong password policies for all user accounts.
  2. BNetwork segmentation between the web application and database tiers.
  3. CImplementing multi-factor authentication (MFA) for web application logins.
  4. DRegular vulnerability scanning of the web application.
Show answer & explanation

Correct answer: B. Network segmentation between the web application and database tiers.

Network segmentation would have created a barrier between the compromised web application tier and the database tier. Even if the web application was breached, the attacker would have faced significant challenges in moving laterally to the database if proper segmentation and access controls were in place, thus limiting the impact.

Why the other options are wrong

  • A. Strong password policies are crucial for preventing initial compromise and credential-based lateral movement, but segmentation acts as a physical barrier even if credentials are compromised.
  • C. MFA for web application logins would help prevent initial access but would not directly limit lateral movement *after* initial compromise if the attacker found another way in or bypassed MFA.
  • D. Regular vulnerability scanning would help identify the initial web application vulnerability but would not prevent lateral movement once the initial breach occurred.

Network Segmentation

The practice of dividing a computer network into multiple smaller segments or subnets, each acting as its own small network, to isolate traffic and limit the scope of a breach.

  • Limits lateral movement.
  • Reduces the blast radius of an attack.
  • Enhances security posture.
  • Implemented with firewalls, VLANs, and ACLs.

Memory trick: Build fences between your valuable assets to slow down intruders.

More Security Operations questions