Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A security analyst is investigating a suspected malware infection on a host within the corporate network. The analyst needs to isolate the host from the rest of the network while maintaining a management connection for remediation. Which network security technology is best suited for this temporary isolation without reconfiguring physical cabling?
- ANetwork Address Translation (NAT)
- BMulticast Routing
- CVirtual Local Area Network (VLAN)
- DQuality of Service (QoS)
Show answer & explanationAnswer & explanation
Correct answer: C. Virtual Local Area Network (VLAN)
VLANs allow logical segmentation of a network, enabling the analyst to move the infected host to an isolated VLAN (quarantine VLAN) while maintaining a separate management VLAN, all without changing physical connections. NAT translates IP addresses but doesn't provide isolation. QoS prioritizes traffic but doesn't isolate hosts. Multicast routing is for efficient one-to-many communication, not host isolation.
Why the other options are wrong
- A. NAT is used for IP address translation and does not provide network segmentation or isolation capabilities.
- B. Multicast routing enables efficient one-to-many communication but is unrelated to host isolation or network segmentation.
- D. QoS manages and prioritizes network traffic but does not isolate hosts or segments them from the network.
VLAN for Isolation
VLANs (Virtual Local Area Networks) can be used to logically segment a network, allowing specific hosts or groups of hosts to be isolated from the rest of the network for security or operational purposes.
- Provides logical segmentation without physical changes.
- Can create 'quarantine' segments for infected hosts.
- Facilitates management access to isolated devices.
Memory trick: Separate your network like a house with many rooms.