SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security operations center (SOC) analyst observes unusual outbound network traffic from an internal server to an unknown external IP address. The traffic pattern is consistent with data exfiltration, but the server is not authorized to initiate external connections. Which of the following security controls would BEST prevent this type of communication in the future?

  1. AData Loss Prevention (DLP) system
  2. BIntrusion Detection System (IDS)
  3. CNetwork Segmentation
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: C. Network Segmentation

Network segmentation, particularly through the use of firewalls and VLANs, can restrict communication between network segments, preventing unauthorized outbound connections from a server. While other options detect or prevent data exfiltration, segmentation directly controls network flow.

Why the other options are wrong

  • A. DLP focuses on preventing sensitive data from leaving the organization, but it may not prevent all unauthorized outbound connections, especially if the data type isn't classified as sensitive by DLP policies.
  • B. An IDS primarily detects suspicious activity but does not prevent the communication itself.
  • D. A SIEM aggregates and analyzes logs, aiding in detection and response, but it does not actively prevent network communication.

Network Segmentation

Network segmentation is the practice of dividing a computer network into smaller, isolated segments, often to improve security and performance.

  • Restricts lateral movement of attackers
  • Limits the blast radius of security incidents
  • Implemented using VLANs, firewalls, and routing technologies

Memory trick: Segment your network, segment your risk, segment your data.

More Security Operations and Administration questions