nerdexam
Cisco

350-201(NEW-127Q) · Question #3

A multinational corporation, with a complex network infrastructure comprising a central data center, several remote offices, and cloud-based services, faces challenges in managing network security…

The correct answer is A. Establish a zero-trust model across the network, segmenting based on user roles and data access needs, applying uniform security policies across all segments, and using SD-WAN to manage traffic between remote offices and the data center. Option A is correct because it addresses all four variables simultaneously: zero-trust handles diverse geographical locations and varying data sensitivity by granting access based on identity/role rather than network location, while SD-WAN optimizes performance and enables…

Network Security

Question

A multinational corporation, with a complex network infrastructure comprising a central data center, several remote offices, and cloud-based services, faces challenges in managing network security and performance. The company has experienced unexpected network traffic, leading to concerns about potential security vulnerabilities and reduced performance for critical applications. To address these issues, the IT team is considering network segmentation and must consider these variables: diverse geographical locations of offices, a mix of critical and non-critical applications, varying levels of data sensitivity, and the need for secure but efficient inter-office communication. How should the IT team apply network segmentation to optimize security and performance?

Options

  • AEstablish a zero-trust model across the network, segmenting based on user roles and data access needs, applying uniform security policies across all segments, and using SD-WAN to manage traffic between remote offices and the data center.
  • BSegment the network based on data sensitivity levels, isolating highly sensitive data in a secure segment with restricted access, and use quality of service policies to prioritize critical application traffic across segments.
  • CCreate segments based on application criticality, with dedicated segments for critical applications to ensure performance, and enforce strict access control and monitoring for segments with sensitive data.
  • DImplement VLANs to segregate traffic based on the geographical location of offices, use VPNs for secure inter-office communication, and apply stricter access controls for segments that handle sensitive data.

How the community answered

(51 responses)
  • A
    69% (35)
  • B
    4% (2)
  • C
    8% (4)
  • D
    20% (10)

Explanation

Option A is correct because it addresses all four variables simultaneously: zero-trust handles diverse geographical locations and varying data sensitivity by granting access based on identity/role rather than network location, while SD-WAN optimizes performance and enables secure inter-office communication across the complex infrastructure. Option B is close but incomplete - prioritizing by data sensitivity alone ignores application criticality and doesn't address the geographic/inter-office communication challenge. Option C focuses on application criticality and access controls but misses the broader architectural need for a trust model that scales across diverse locations and user roles. Option D uses geography as the primary segmentation criterion (VLANs per office), which creates administrative overhead and doesn't inherently address data sensitivity or application performance - VLANs and VPNs alone are reactive tools, not a holistic security strategy.

Memory tip: Think "A covers ALL" - when a question lists multiple complex variables (geography, sensitivity, criticality, performance), the correct answer is almost always the one that addresses every variable with a unified framework (zero-trust + SD-WAN) rather than solutions that optimize for just one or two dimensions.

Topics

#Network Segmentation#Zero Trust Architecture#SD-WAN#Access Control

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice