Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A security architect is designing a new cloud-based microservices application. To enhance security, each microservice will run in its own isolated container, and strict network policies will be applied to control communication between them. This approach aims to minimize the impact of a compromise on one service by preventing it from easily affecting others. Which security principle is primarily being applied here?
- AIsolation
- BLeast Privilege
- CSeparation of Duties
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Isolation
The scenario emphasizes running each microservice in its 'own isolated container' with 'strict network policies' to 'minimize the impact of a compromise' by preventing lateral movement. This directly describes the security principle of Isolation, which aims to separate resources to contain threats.
Why the other options are wrong
- B. Least Privilege concerns granting only necessary permissions to users or processes, not the containment of services.
- C. Separation of Duties prevents a single individual from completing a critical task, focusing on human roles.
- D. Defense in Depth involves multiple layers of security controls, but Isolation is a more specific principle at play here.
Isolation
A security principle that involves separating resources, processes, or data to prevent a compromise in one area from affecting others. It helps to contain threats and limit the blast radius of an attack.
- Achieved through techniques like containerization, virtualization, and network segmentation.
- Minimizes the impact of a security incident.
- Enhances system resilience and reduces attack surface.
- A core component of secure system design.
Memory trick: Secure Design Isolates Privileged Layers