Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2ArchitectureHard
A network security team is implementing a solution to prevent lateral movement of threats within its campus network. The goal is to isolate different user groups and critical servers from each other, even if they reside on the same subnet, without requiring extensive VLAN reconfigurations or physical network changes. Which technology is most effective for achieving this granular level of isolation?
- AFirewall zones at the network perimeter
- BVRFs (Virtual Routing and Forwarding)
- CTraditional VLANs with ACLs
- DMicrosegmentation using SGTs (Scalable Group Tags)
Show answer & explanationAnswer & explanation
Correct answer: D. Microsegmentation using SGTs (Scalable Group Tags)
Microsegmentation, particularly using Scalable Group Tags (SGTs) in solutions like Cisco SD-Access or Cisco TrustSec, allows for granular policy enforcement between individual endpoints or groups, regardless of their IP address or VLAN. This directly addresses the need to prevent lateral movement and isolate groups even on the same subnet without extensive reconfigurations.
Why the other options are wrong
- A. Firewall zones at the network perimeter protect from external threats but do not address lateral movement within the internal campus network across different user groups and servers.
- B. VRFs provide full routing table isolation, segmenting the network into completely separate routing domains, which is too broad for isolating groups on the same subnet and preventing lateral movement within a single logical network.
- C. Traditional VLANs with ACLs provide segmentation at a subnet level, but microsegmentation requires more granular control, often within the same VLAN, and can become complex to manage.
Microsegmentation
A network security technique that creates secure zones in data centers and cloud environments, allowing organizations to isolate workloads and secure them individually.
- Granular policy enforcement at the workload or endpoint level.
- Reduces the attack surface by preventing lateral movement.
- Independent of network topology (VLANs, IP addresses).
- Often implemented using SGTs, VXLAN, or host-based firewalls.
Memory trick: Segmentation: VLANs, VRFs, Micros, Firewalls - Choose your barrier.