Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A security engineer is designing a secure network access solution for a new data center that hosts critical applications. The design must ensure that only authorized servers can communicate with each other, minimizing the attack surface even if a server is compromised. Traditional VLANs are deemed insufficient due to flat access control capabilities within a VLAN. Which approach using Cisco technologies would best achieve this granular segmentation and policy enforcement within the data center?

  1. AConfiguring Private VLANs (PVLANs) to isolate servers within a broadcast domain.
  2. BDeploying Cisco TrustSec with Security Group Tags (SGTs) and Security Group Access Control Lists (SGACLs).
  3. CImplementing a large number of micro-VLANs for each server.
  4. DUtilizing Port Security on all server-facing switch ports.
Show answer & explanation

Correct answer: B. Deploying Cisco TrustSec with Security Group Tags (SGTs) and Security Group Access Control Lists (SGACLs).

Cisco TrustSec with SGTs and SGACLs provides identity-based micro-segmentation, allowing for granular control over server-to-server communication based on security group membership, independent of network topology. This significantly reduces the attack surface. Micro-VLANs are complex and scale poorly, Port Security is for MAC address control, and PVLANs offer isolation within a broadcast domain but not dynamic identity-based policy enforcement across the data center.

Why the other options are wrong

  • A. PVLANs isolate ports within a VLAN, preventing direct communication between specified ports, but they are not identity-based and can become complex for a large number of servers with dynamic communication needs.
  • C. Implementing many micro-VLANs is complex to manage, does not provide identity-based control, and still suffers from flat access within a VLAN.
  • D. Port Security binds MAC addresses to ports, preventing unauthorized devices from connecting, but does not provide granular server-to-server communication control based on identity.

Cisco TrustSec Micro-segmentation

A security architecture that uses Security Group Tags (SGTs) to classify network traffic based on user or device identity, enabling granular, identity-based policy enforcement (SGACLs) for micro-segmentation.

  • Reduces attack surface by limiting lateral movement.
  • Policies are identity-based, not IP-based.
  • Simplifies network segmentation management.

Memory trick: For critical data, tag and segment every server based on its role, not just its location.

More Endpoint Security and Secure Network Access questions