Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A company is implementing a new security policy that requires all internal network traffic between different departments (e.g., Finance and HR) to be isolated from each other, even though they reside on the same physical network infrastructure. This isolation should prevent direct communication unless explicitly allowed by specific security rules. Which network security concept is being applied here?
- AStateful Firewall
- BDemilitarized Zone (DMZ)
- CNetwork Segmentation
- DNetwork Address Translation (NAT)
Show answer & explanationAnswer & explanation
Correct answer: C. Network Segmentation
Network segmentation involves dividing a network into smaller, isolated segments. This allows for granular control over traffic flow between segments, enhancing security by limiting the blast radius of a breach and enforcing specific security policies between different departmental networks.
Why the other options are wrong
- A. A stateful firewall inspects and filters traffic based on connection state, but it is a tool used within a segmented network, not the concept of segmentation itself.
- B. A DMZ is a specific network segment for public-facing servers, not for internal departmental isolation.
- D. NAT modifies IP addresses in packet headers, primarily for internet access or hiding internal IPs, not for internal network isolation.
Network Segmentation
The practice of dividing a computer network into smaller subnetworks, each acting as its own isolated network segment.
- Enhances security by limiting lateral movement of threats.
- Improves network performance by reducing broadcast domains.
- Facilitates compliance with regulatory requirements.
- Can be implemented using VLANs, firewalls, or SDN.
Memory trick: Like dividing a big office into smaller, locked departments, each with its own rules.