Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A cybersecurity analyst is investigating a network intrusion where an attacker gained unauthorized access to internal systems by exploiting a vulnerability in a web application. The attacker then used this access to pivot to other servers within the network. Which security concept, if properly implemented, would have best limited the attacker's ability to move laterally across the network after the initial compromise?
- AIntrusion Detection System (IDS)
- BData Loss Prevention (DLP)
- CMicrosegmentation
- DNetwork Access Control (NAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsegmentation
Microsegmentation confines network traffic within smaller, logically isolated segments, making it significantly harder for an attacker who has compromised one segment to move laterally to others. While other options provide security benefits, microsegmentation directly addresses lateral movement.
Why the other options are wrong
- A. An IDS detects intrusions but doesn't inherently prevent lateral movement after an initial breach.
- B. DLP focuses on preventing sensitive data from leaving the network, not on restricting internal lateral movement.
- D. NAC controls initial access to the network but doesn't prevent lateral movement once a device is authenticated.
Microsegmentation
Microsegmentation is a security technique that creates isolated network segments for individual workloads or applications, allowing for fine-grained security policies.
- Enhances East-West traffic control
- Limits lateral movement of attackers
- Applies granular security policies
Memory trick: Segment the network like tiny, secure rooms.