A company is implementing a new network segment for IoT devices. The security policy dictates that these devices should only be allowed to communicate with a specific MQTT broker server located in the DMZ, and no other internal or external resources. The IoT devices are in the 'IoT-Zone' and the MQTT broker is in the 'DMZ-Zone'. Which combination of security policy rules and settings would best enforce this requirement?
- AOne allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.
- BTwo allow rules: 1) Source=IoT-Zone, Destination=DMZ-Zone, Application=any, Service=any, Destination Address=MQTT_Broker_IP. 2) Source=IoT-Zone, Destination=any, Application=MQTT, Service=application-default. Followed by a deny-all rule for IoT-Zone.
- COne allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=any. Followed by a deny-all rule for IoT-Zone.
- DOne allow rule: Source=any, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.
Show answer & explanationAnswer & explanation
Correct answer: A. One allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.
To strictly allow communication only to the specific MQTT broker, the allow rule must specify the IoT-Zone as the source, the DMZ-Zone as the destination, the MQTT application, and crucially, the specific IP address of the MQTT broker. A subsequent deny-all rule for the IoT-Zone ensures no other traffic is permitted.
Why the other options are wrong
- B. The first rule is too broad (Application=any, Service=any), allowing any traffic to the MQTT broker. The second rule is too broad on destination. This does not meet the 'only communicate with a specific MQTT broker' requirement.
- C. This rule uses 'Destination Address=any', which would allow IoT devices to communicate with any device in the DMZ-Zone using MQTT, not just the specific broker.
- D. This rule uses 'Source=any', which would allow any source to communicate with the MQTT broker, not just the IoT devices, and doesn't explicitly restrict IoT devices from reaching other destinations.
Least Privilege Security Policy
A security principle that dictates that a user, program, or process should be given only the minimum privileges necessary to perform its function, often implemented with specific allow rules followed by a general deny rule.
- Grant only necessary access.
- Minimize attack surface.
- Often implemented with specific 'allow' rules and broad 'deny' rules.
Memory trick: IoT rules: Specific Source, Specific Dest, Specific App, Specific IP, then DENY ALL.