A network security team is designing a network segmentation strategy for a university campus. The goal is to isolate student, faculty, and guest networks, as well as critical research labs and administrative systems, to limit the blast radius of potential security breaches. The solution must allow for dynamic policy application based on user identity and device posture. Which network security architecture is best suited to meet these requirements?
- ANetwork Access Control (NAC) with static assignments
- BVLAN-based segmentation with ACLs
- CFirewall-based segmentation at network perimeters
- DMicrosegmentation using Software-Defined Access (SD-Access)
Show answer & explanationAnswer & explanation
Correct answer: D. Microsegmentation using Software-Defined Access (SD-Access)
SD-Access, a Cisco implementation of Software-Defined Networking for the campus, provides microsegmentation using Virtual Networks (VNs) and Scalable Group Tags (SGTs). This allows for dynamic policy application based on user identity and device posture, effectively isolating different user groups and critical resources, fulfilling the requirement for limiting the blast radius with dynamic policies.
Why the other options are wrong
- A. NAC with static assignments lacks the dynamic, granular segmentation capabilities required for microsegmentation and limiting the blast radius effectively across diverse user groups.
- B. VLANs with ACLs provide basic segmentation but are static, complex to manage at scale, and don't offer dynamic policy application based on identity or posture.
- C. Firewall-based segmentation is effective at network perimeters but typically operates at coarser granularity and struggles with dynamic, identity-based segmentation within the campus.
SD-Access Microsegmentation
A feature of Cisco SD-Access that enables granular security segmentation within the campus network, applying policies based on user identity and device posture, independent of network topology.
- Uses Virtual Networks (VNs) for macro-segmentation.
- Uses Scalable Group Tags (SGTs) for micro-segmentation.
- Enables dynamic policy enforcement and limits blast radius.
Memory trick: SD-Access tags users, firewall guards doors, VLANs draw lines.