Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard
A security auditor is reviewing a company's network security architecture and notes that critical internal servers (e.g., database servers, application servers) are directly accessible from the public-facing web servers in the DMZ. This configuration is considered a significant security risk. Which network security best practice is being violated?
- AProper Network Segmentation
- BDeployment of a Next-Generation Firewall (NGFW)
- CUse of Intrusion Detection Systems (IDS)
- DImplementation of Network Address Translation (NAT)
Show answer & explanationAnswer & explanation
Correct answer: A. Proper Network Segmentation
Proper network segmentation dictates that critical internal assets should be isolated from less secure zones like the DMZ. Direct accessibility of internal servers from the DMZ violates this principle, creating a flat network that increases the attack surface.
Why the other options are wrong
- B. While an NGFW is a powerful tool for enforcing segmentation rules, its deployment alone doesn't guarantee proper segmentation if the architecture itself allows direct, uncontrolled access.
- C. IDS detects malicious activity but does not prevent direct access between network segments; it's a detective control, not a preventative architectural control.
- D. NAT is for IP address translation and doesn't directly address the logical separation of network zones for security purposes.
Network Segmentation
The practice of dividing a computer network into smaller, isolated sub-networks or segments to improve security, performance, and manageability.
- Limits the blast radius of a breach.
- Enforces granular access control between segments.
- Commonly implemented with firewalls, VLANs, and routers.
Memory trick: Good security is like building a castle with distinct, protected wards.