Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2ArchitectureHard

A network security team is designing a network segmentation strategy for a university campus. The goal is to isolate student, faculty, and guest traffic, and to prevent lateral movement of threats between these groups, even if a compromise occurs within one segment. Which network security concept is most effective for achieving this granular isolation?

  1. ANetwork Address Translation (NAT)
  2. BVLANs with Access Control Lists (ACLs)
  3. CMicrosegmentation
  4. DFirewall zones
Show answer & explanation

Correct answer: C. Microsegmentation

Microsegmentation provides granular isolation down to the workload level, allowing policies to be defined for individual applications or endpoints, thereby effectively preventing lateral movement of threats even within a seemingly isolated segment.

Why the other options are wrong

  • A. NAT is used for address translation and does not inherently provide network segmentation or security isolation capabilities for preventing lateral threat movement.
  • B. VLANs with ACLs provide basic network segmentation but are less granular and can be complex to manage at scale for preventing lateral movement within a large university.
  • D. Firewall zones provide macro-segmentation between larger network areas but do not offer the fine-grained control needed to prevent lateral movement within a zone or between individual devices.

Microsegmentation

Microsegmentation is a network security technique that creates secure zones in data centers or cloud environments, allowing organizations to isolate workloads from one another and secure them individually.

  • Granular security policy enforcement at the workload level.
  • Prevents lateral movement of threats.
  • Enhances security posture within network segments.

Memory trick: Microsegmentation: My Individual Compartments Offer Security.

More Architecture questions