Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A security architect is designing a solution for a critical industrial control system (ICS) network. The requirement is to ensure that even if a workstation connected to the ICS network is compromised, the impact is limited, and the attacker cannot easily move to other segments of the ICS or the corporate network. Which network security architecture principle is paramount in this design?
- AFlat Network Design
- BDefense in Depth
- CSingle Point of Failure
- DImplicit Trust
Show answer & explanationAnswer & explanation
Correct answer: B. Defense in Depth
Defense in Depth involves using multiple layers of security controls to protect resources. If one control fails or is bypassed (e.g., a workstation is compromised), other controls are still in place to limit the impact and prevent lateral movement.
Why the other options are wrong
- A. A flat network design provides minimal segmentation and would allow an attacker to move easily across the network, directly contradicting the requirement.
- C. A single point of failure is a design flaw that would compromise the entire security posture if that one component fails, which is the opposite of the desired resilience.
- D. Implicit trust assumes that anything inside the network is trustworthy, which is a dangerous principle that Zero Trust aims to eliminate and would facilitate lateral movement.
Defense in Depth
Defense in Depth is a security strategy that employs multiple layers of security controls (administrative, technical, physical) to protect an organization's assets. If one layer fails, another layer is there to provide protection.
- Creates redundant security measures.
- Aims to slow down and complicate attacks.
- Applies across physical, technical, and administrative domains.
Memory trick: Defense in Depth: like an onion, layers protect the core.