Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network security team is implementing a new threat defense strategy. They want to ensure that all internal network segments are protected from lateral movement of threats. Specifically, they need to segment the network into micro-segments and apply granular security policies between workloads, regardless of their physical location or underlying network infrastructure. Which security concept is best suited for this approach?

  1. ANetwork Access Control (NAC)
  2. BDistributed Denial of Service (DDoS) Mitigation
  3. CPerimeter Security
  4. DZero Trust Security
Show answer & explanation

Correct answer: D. Zero Trust Security

Zero Trust Security is a security model that operates on the principle of 'never trust, always verify.' It emphasizes micro-segmentation and granular access control policies applied to every workload and user, treating all network traffic as potentially hostile, regardless of whether it originates inside or outside the network. This directly addresses protecting against lateral movement within internal segments.

Why the other options are wrong

  • A. Network Access Control (NAC) primarily focuses on authenticating and authorizing devices/users connecting to the network edge, not granular workload-to-workload segmentation within the network.
  • B. Distributed Denial of Service (DDoS) Mitigation protects against overwhelming traffic attacks, which is a different security concern.
  • C. Perimeter Security focuses on protecting the network boundary from external threats, not internal lateral movement.

Zero Trust Security

A security model that assumes no user or device, whether inside or outside the network, should be trusted by default. All access requests are authenticated, authorized, and continuously validated.

  • Core principle: 'Never trust, always verify'.
  • Emphasizes micro-segmentation and granular access control.
  • Helps prevent lateral movement of threats within the network.
  • Requires strong identity verification and continuous monitoring.

Memory trick: Security Models: Trust Zero, Control Access, Guard Perimeter, Stop DDoS

More Security questions