Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard
A company is implementing new security protocols to protect its internal network. One of the key requirements is to ensure that all internal network traffic between different departments (e.g., HR, Finance, IT) cannot directly communicate without passing through a security gateway, even if they reside on the same physical network infrastructure. This approach aims to limit the lateral movement of potential attackers. What network security concept is being implemented here?
- AVLAN Tagging
- BNetwork Address Translation (NAT)
- CMicrosegmentation
- DDemilitarized Zone (DMZ)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsegmentation
Microsegmentation creates isolated security zones for individual workloads or applications, even within the same subnet, allowing for granular control over traffic flow and limiting lateral movement, which aligns with the scenario's goal of departmental isolation.
Why the other options are wrong
- A. VLAN Tagging segregates broadcast domains at Layer 2 but doesn't inherently enforce security policies between VLANs without a router/firewall.
- B. NAT translates IP addresses and is used for connecting private networks to public ones, not for internal departmental isolation.
- D. DMZ is used to secure public-facing servers from the internal network, not for isolating internal departments from each other.
Microsegmentation
A security technique that divides data centers into distinct secure segments down to the individual workload level, allowing granular policy enforcement.
- Creates isolated security zones within a network.
- Limits lateral movement of attackers.
- Enforces granular security policies between applications or workloads.
Memory trick: Microsegmentation: Tiny segments for maximum isolation.