Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A network security architect is designing a secure industrial control system (ICS) network. The design requires strict isolation between different operational zones and critical assets, ensuring that communication is only permitted between explicitly authorized systems and services. Which security principle is being primarily applied in this design?

  1. ALeast Privilege
  2. BZero Trust
  3. CDefense in Depth
  4. DMicro-segmentation
Show answer & explanation

Correct answer: D. Micro-segmentation

Micro-segmentation focuses on creating granular security zones within a network, isolating individual workloads or applications. This aligns with the requirement for strict isolation between different operational zones and critical assets, allowing only explicitly authorized communication.

Why the other options are wrong

  • A. Least Privilege restricts user or process access rights, not network communication between systems at a granular level.
  • B. Zero Trust is a broader security model, and micro-segmentation is a key enabling technology for it, but the question specifically describes the granular isolation aspect.
  • C. Defense in Depth involves multiple layers of security, but doesn't specifically address granular isolation within the network.

Micro-segmentation

A security technique that creates granular security zones within a data center or cloud environment, allowing security policies to be applied to individual workloads.

  • Isolates individual applications or workloads.
  • Reduces the attack surface by limiting lateral movement.
  • Enables fine-grained access control policies.

Memory trick: Think of building many small, locked rooms inside a larger building.

More Network Security questions