Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A managed security service provider (MSSP) is advising a client on securing their cloud infrastructure. The client wants to ensure that virtual machines (VMs) running sensitive applications are isolated from other VMs in the same cloud environment, even if they reside on the same physical host. Which security concept should the MSSP recommend?
- ANetwork Address Translation (NAT)
- BVirtual Private Network (VPN)
- CMicro-segmentation
- DDemilitarized Zone (DMZ)
Show answer & explanationAnswer & explanation
Correct answer: C. Micro-segmentation
Micro-segmentation provides granular isolation for individual workloads (like VMs) within a data center or cloud environment, even down to applications, ensuring that security policies are applied between them rather than just at the perimeter.
Why the other options are wrong
- A. NAT translates IP addresses and is used for address conservation or hiding internal topology, not for isolating workloads within a cloud environment.
- B. VPNs provide secure, encrypted tunnels over an untrusted network, typically for remote access or site-to-site connectivity, not for isolating VMs within the same cloud.
- D. A DMZ is a network segment that provides a buffer between an untrusted network (like the internet) and an organization's internal network, not for isolating VMs from each other internally.
Micro-segmentation
Micro-segmentation is a security technique that divides a data center or cloud network into highly granular, isolated segments down to the individual workload level, allowing for precise security policy enforcement.
- Enhances East-West traffic security.
- Reduces the attack surface and lateral movement.
- Often implemented using software-defined networking (SDN) or hypervisor-level controls.
Memory trick: Micro-segmentation: tiny fences for every cloud VM.