Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard
A network security engineer is designing a secure network architecture for a critical infrastructure system. The design requires that network devices (routers, switches) and servers hosting critical applications are physically isolated from the general corporate network. This isolation prevents direct access from less trusted segments and limits the impact of a breach in the corporate network. Which network design concept is being applied here?
- AZero Trust Architecture
- BCloud Security Posture Management (CSPM)
- CDemilitarized Zone (DMZ)
- DNetwork Segmentation
Show answer & explanationAnswer & explanation
Correct answer: D. Network Segmentation
Network segmentation involves dividing a computer network into multiple smaller network segments or subnets. The goal is to improve security by isolating critical systems from less trusted parts of the network, controlling traffic flow between segments, and limiting the scope of a breach.
Why the other options are wrong
- A. Zero Trust is a security model where no user or device is trusted by default, regardless of location; it's an overarching philosophy, not a physical network design concept for isolation.
- B. CSPM manages security configurations and compliance for cloud environments; it's not a network design concept for on-premise physical isolation.
- C. A DMZ is a specific type of network segment used for public-facing servers, but the broader concept of isolating *all* critical devices from the general network is segmentation.
Network Segmentation
The practice of dividing a computer network into smaller, isolated segments or subnets to improve security, performance, and manageability.
- Isolates critical assets from less trusted segments.
- Limits the lateral movement of attackers.
- Implemented using VLANs, firewalls, and routing.
Memory trick: Segmentation Separates Sensitive Systems.