Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium
An organization is migrating its data center and needs to implement a new network design that ensures traffic from the client-facing web servers in the 'Web-DMZ' zone can only access the backend application servers in the 'App-DMZ' zone, and only on specific application ports. No direct internet access should be allowed from 'App-DMZ' servers. Which of the following security zone design principles is primarily being applied?
- APerimeter Security
- BMicro-segmentation
- CDefense in Depth
- DZero Trust
Show answer & explanationAnswer & explanation
Correct answer: B. Micro-segmentation
This scenario describes micro-segmentation, where network segments (Web-DMZ, App-DMZ) are isolated from each other with granular security policies applied between them. This limits lateral movement and ensures that only necessary traffic flows between specific application components, enhancing security within the data center.
Why the other options are wrong
- A. Perimeter security focuses on protecting the network's external boundary, not internal data center segmentation.
- C. Defense in Depth is a strategy using multiple layers of security, but micro-segmentation is a specific technique that enables it within the data center.
- D. Zero Trust is a security model where no entity is trusted by default, but micro-segmentation is a technical implementation that supports a Zero Trust architecture, not the model itself.
Micro-segmentation
Micro-segmentation is a network security technique that logically divides a data center network into distinct, isolated segments down to the individual workload level, applying granular security policies between them.
- Reduces attack surface.
- Limits lateral movement of threats.
- Enables granular policy enforcement.
- Key component of Zero Trust architectures.
Memory trick: For tight control, 'SEGMENT' your network into tiny 'BLOCKS'.