Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

A large enterprise is implementing micro-segmentation within its data center to isolate individual workloads and applications. They require a solution that can apply granular security policies between virtual machines (VMs) and containers, regardless of their physical location, based on attributes like application role, operating system, and security context. Which technology best facilitates this advanced segmentation strategy?

  1. ASoftware-Defined Networking (SDN) with Network Virtualization
  2. BHardware-based firewalls at the hypervisor level
  3. CTraditional VLANs with ACLs
  4. DPhysical network segmentation with dedicated switches
Show answer & explanation

Correct answer: A. Software-Defined Networking (SDN) with Network Virtualization

Software-Defined Networking (SDN) with network virtualization (e.g., NSX-T, ACI) is the ideal solution for micro-segmentation. It decouples the control plane from the data plane, allowing for policy-driven, granular segmentation of virtual workloads (VMs, containers) based on attributes rather than IP addresses or physical topology. This enables consistent policy enforcement regardless of workload location.

Why the other options are wrong

  • B. While hypervisor-level firewalls exist, they are often part of a broader SDN/network virtualization solution. Implementing them in a purely 'hardware-based' fashion at scale for granular, attribute-based policies is not the most efficient or flexible approach compared to SDN.
  • C. Traditional VLANs with ACLs are static and IP-based, making them cumbersome and inefficient for granular micro-segmentation of dynamic virtual workloads. They don't easily scale with application roles or security context.
  • D. Physical network segmentation is effective for broad isolation but is impractical and cost-prohibitive for micro-segmentation between individual VMs and containers, especially when workloads are dynamic and move between hosts.

Micro-segmentation (SDN)

A network security technique that creates granular security zones for individual workloads (VMs, containers) within a data center, allowing for distinct security policies to be applied to each workload.

  • Enforced by Software-Defined Networking (SDN) and network virtualization.
  • Policies are attribute-based (e.g., application, OS, user role).
  • Reduces the attack surface and limits lateral movement of threats.

Memory trick: Cutting the network into tiny, secure slices for every app.

More Visibility and Enforcement questions