Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy
A network security engineer is designing a solution to protect internal network segments from unauthorized lateral movement. The design requires granular control over traffic flow between virtual machines within the same subnet, without hair-pinning traffic to a physical firewall. Which technology best addresses this requirement?
- AMicro-segmentation with Distributed Firewalls
- BDemilitarized Zone (DMZ)
- CNetwork Address Translation (NAT)
- DStateless Packet Filtering
Show answer & explanationAnswer & explanation
Correct answer: A. Micro-segmentation with Distributed Firewalls
Micro-segmentation with distributed firewalls allows for granular security policies to be applied at the workload level, even for traffic within the same subnet, preventing unauthorized lateral movement without requiring traffic to traverse a physical appliance.
Why the other options are wrong
- B. A DMZ is a network segment for public-facing servers; it does not address internal lateral movement between VMs.
- C. NAT is used for IP address translation and does not provide granular security control between internal segments.
- D. Stateless packet filtering lacks the stateful inspection and granular control needed for dynamic VM environments.
Micro-segmentation
A security technique that logically divides a data center into distinct, isolated security segments down to the individual workload level, allowing for granular policy enforcement.
- Enhances East-West traffic security.
- Reduces the attack surface by isolating workloads.
- Often implemented using distributed firewalls or SDN.
Memory trick: Segment your data center, secure your crown jewels.