Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A government agency is modernizing its IT infrastructure and adopting a Zero Trust architecture. They have a highly sensitive application that processes classified data, residing in an isolated network segment. Access to this application must be strictly controlled, allowing only specific authorized microservices to communicate with it, and blocking all other traffic. This isolation needs to be enforced at the network layer. Which Zero Trust concept is being applied here?
- ALeast Privilege Access
- BIdentity Governance
- CMicro-segmentation
- DDevice Compliance
Show answer & explanationAnswer & explanation
Correct answer: C. Micro-segmentation
Micro-segmentation involves dividing a network into small, isolated segments, down to individual workloads, and applying granular security policies to each segment. This allows for strict control over communication pathways, ensuring only authorized traffic can flow between specific application components, which is critical for isolating sensitive applications.
Why the other options are wrong
- A. Least Privilege Access focuses on user permissions, not network isolation between application components.
- B. Identity Governance manages user identities and their lifecycle, not network traffic flow.
- D. Device Compliance ensures devices meet security standards, but doesn't directly control network communication between microservices.
Micro-segmentation (Zero Trust)
A security technique that divides data centers and cloud environments into distinct, isolated security segments down to the individual workload level, allowing granular control over traffic flow.
- Limits lateral movement of threats within the network.
- Enforces granular policies between workloads.
- Reduces the attack surface.
- Fundamental for Zero Trust network security.
Memory trick: Micro-segmentation: Tiny walls for tiny traffic.