Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A security auditor is reviewing an organization's network architecture and discovers that all internal network segments (e.g., HR, Finance, R&D) are directly connected to each other without any intermediary security devices or access controls. This allows any compromised device in one segment to potentially access resources in any other segment. Which security best practice is most notably absent in this architecture?
- ANetwork Segmentation
- BLoad Balancing
- CNetwork Address Translation (NAT)
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Segmentation
Network segmentation involves dividing a network into smaller, isolated segments, often with security controls between them. The absence of such divisions, allowing direct access between sensitive segments, indicates a lack of network segmentation.
Why the other options are wrong
- B. Load balancing distributes traffic across servers for performance, unrelated to internal network security isolation.
- C. NAT translates IP addresses but doesn't provide internal network isolation or access control between segments.
- D. VPNs provide secure remote access or site-to-site tunnels, not internal network isolation between segments.
Network Segmentation
The practice of dividing a computer network into smaller, isolated sub-networks or segments to improve security, control traffic, and limit the impact of a breach.
- Limits lateral movement of attackers.
- Contains breaches to specific segments.
- Enables granular security policy enforcement.
Memory trick: Divide your network into rooms, so a fire in one doesn't burn down the whole house.