Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A cybersecurity analyst is investigating an incident where an internal server was compromised by malware that spread quickly across the network. The malware was able to evade detection by the existing antivirus software. Which of the following security controls would have been most effective in preventing the spread of this malware within the network by isolating the compromised server?
- APhysical security measures
- BRegular software updates
- CStrong password policies
- DNetwork segmentation
Show answer & explanationAnswer & explanation
Correct answer: D. Network segmentation
Network segmentation divides a network into smaller, isolated segments. This limits the lateral movement of malware, preventing it from spreading rapidly from a compromised server to other parts of the network.
Why the other options are wrong
- A. Physical security measures protect hardware but do not prevent malware spread once a server is logically compromised and connected to the network.
- B. Regular software updates help prevent initial compromise but wouldn't isolate an already compromised server from spreading malware.
- C. Strong password policies prevent unauthorized access but do not directly address the spread of malware once a system is compromised.
Network Segmentation
Network segmentation is the practice of dividing a computer network into smaller subnetworks, each acting as its own isolated network segment.
- Limits lateral movement of threats.
- Improves security posture by containing breaches.
- Enhances network performance and simplifies management.
Memory trick: Segment your network, and malware will hit a 'wall' before it spreads.