200-201 · Question #400
Which description is a defense-in-depth principal strategy?
The correct answer is B. implementing VLANs to segment network traffic. Implementing VLANs to segment network traffic is a defense-in-depth strategy that creates multiple layers of security by logically separating network segments, restricting lateral movement and containing potential breaches.
Question
Which description is a defense-in-depth principal strategy?
Options
- Aisolating employees with access to critical data
- Bimplementing VLANs to segment network traffic
- Cdeveloping approval flow for new hires
- Ddesigning Active Directory groups
How the community answered
(20 responses)- A5% (1)
- B90% (18)
- D5% (1)
Why each option
Implementing VLANs to segment network traffic is a defense-in-depth strategy that creates multiple layers of security by logically separating network segments, restricting lateral movement and containing potential breaches.
While a form of control, isolating employees is not a primary 'defense-in-depth' technical network or system strategy, but rather an administrative or physical control measure.
Implementing VLANs (Virtual Local Area Networks) to segment network traffic is a classic defense-in-depth strategy. It creates logical boundaries within a physical network, preventing unauthorized access between different segments and limiting the blast radius of a successful breach, thereby adding a layer of protection.
Developing an approval flow for new hires is an administrative security control related to onboarding and access management, not a technical defense-in-depth strategy.
Designing Active Directory groups is an administrative task for managing permissions and roles, which supports security but is not a standalone defense-in-depth strategy itself.
Concept tested: Defense-in-depth strategies (network segmentation)
Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-network-segmentation
Topics
Community Discussion
No community discussion yet for this question.