Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2ArchitectureHard
A network security team is designing a network segmentation strategy for a university campus. The goal is to isolate student, faculty, and guest traffic, and to prevent lateral movement of threats between these groups, even if a compromise occurs within one segment. Which network security concept is most effective for achieving this granular isolation?
- ANetwork Address Translation (NAT)
- BVLANs with Access Control Lists (ACLs)
- CMicrosegmentation
- DFirewall zones
Show answer & explanationAnswer & explanation
Correct answer: C. Microsegmentation
Microsegmentation provides granular isolation down to the workload level, allowing policies to be defined for individual applications or endpoints, thereby effectively preventing lateral movement of threats even within a seemingly isolated segment.
Why the other options are wrong
- A. NAT is used for address translation and does not inherently provide network segmentation or security isolation capabilities for preventing lateral threat movement.
- B. VLANs with ACLs provide basic network segmentation but are less granular and can be complex to manage at scale for preventing lateral movement within a large university.
- D. Firewall zones provide macro-segmentation between larger network areas but do not offer the fine-grained control needed to prevent lateral movement within a zone or between individual devices.
Microsegmentation
Microsegmentation is a network security technique that creates secure zones in data centers or cloud environments, allowing organizations to isolate workloads from one another and secure them individually.
- Granular security policy enforcement at the workload level.
- Prevents lateral movement of threats.
- Enhances security posture within network segments.
Memory trick: Microsegmentation: My Individual Compartments Offer Security.