Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A cyber-physical system used in an industrial control environment requires strong protection against both external network attacks and unauthorized internal access. Due to the critical nature of the system, any security solution must introduce minimal latency and ensure deterministic communication. Which network security architecture is best suited for segmenting such a system while meeting these strict performance and reliability requirements?

  1. ACloud-based Security Gateway
  2. BMicro-segmentation
  3. CDemilitarized Zone (DMZ)
  4. DFlat Network Design
Show answer & explanation

Correct answer: B. Micro-segmentation

Micro-segmentation provides granular security policies down to the individual workload level, isolating critical systems and applications from each other and from the rest of the network. This approach significantly reduces the attack surface and lateral movement, which is crucial for ICS/SCADA environments, while allowing for direct, low-latency communication between authorized components without traversing numerous traditional firewalls.

Why the other options are wrong

  • A. Cloud-based security gateways typically introduce latency and dependency on external services, which might not be suitable for critical, real-time industrial control systems.
  • C. DMZ protects services exposed to the internet but doesn't provide granular internal segmentation for critical internal systems.
  • D. A flat network design offers no segmentation and is highly vulnerable, directly contradicting the security requirements.

Micro-segmentation

A security technique that creates secure zones in data centers and cloud environments, allowing organizations to isolate workloads and secure them individually.

  • Granular policy enforcement
  • Reduces lateral movement of threats
  • Often implemented with SDN or virtualization

Memory trick: Tiny segments, strong walls.

More Network Security questions