350-201 · Question #9
Refer to the exhibit. An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which…
The correct answer is A. Use VLANs to segregate zones and the firewall to allow only required services and secured. Combining VLAN-based network segmentation with firewall rules that permit only required, encrypted services directly removes both the lateral movement path and the insecure protocol vector the attacker exploited.
Question
Refer to the exhibit. An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which action prevents this type of attack in the future?
Exhibit
Options
- AUse VLANs to segregate zones and the firewall to allow only required services and secured
- BDeploy a SOAR solution and correlate log alerts from customer zones
- CDeploy IDS within sensitive areas and continuously update signatures
- DUse syslog to gather data from multiple sources and detect intrusion logs for timely responses
How the community answered
(50 responses)- A78% (39)
- B6% (3)
- C4% (2)
- D12% (6)
Why each option
Combining VLAN-based network segmentation with firewall rules that permit only required, encrypted services directly removes both the lateral movement path and the insecure protocol vector the attacker exploited.
VLANs isolate the sensitive customer data zone from general workstation segments, ensuring that a compromised workstation has no direct Layer 2 or Layer 3 path to sensitive resources without passing through an enforced security boundary. Firewall policies configured to allow only required services and secured protocols block insecure protocols such as Telnet, FTP, and HTTP that the attacker used to exfiltrate data. This combination addresses both the network access vector and the insecure protocol weakness simultaneously, preventing the same class of attack in the future.
SOAR improves detection and automated response speed but provides no enforcement mechanism to block insecure protocols or prevent lateral movement between network zones.
IDS sensors detect and alert on malicious traffic patterns but cannot enforce segmentation or block insecure protocol sessions, leaving the underlying attack vector open.
Syslog aggregation supports log analysis and post-incident investigation but offers no preventive control over network access paths or the use of insecure protocols.
Concept tested: Network segmentation with VLANs and firewall policy to block insecure protocols
Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/SAFE_RG/SAFE_rg.html
Topics
Community Discussion
No community discussion yet for this question.
