400-007 · Question #387
In the wake of a security compromise incident where the internal networks were breached by an outside attacker at the perimeter of the infrastructure, an enterprise is now evaluating potential…
The correct answer is B. segmentation E. microperimeters. Network segmentation and microperimeters are complementary Zero Trust-aligned design strategies that limit lateral movement and contain damage after an attacker breaches the outer network perimeter.
Question
In the wake of a security compromise incident where the internal networks were breached by an outside attacker at the perimeter of the infrastructure, an enterprise is now evaluating potential measures that can help protect against the same type of incident in the future. What are two design options that can be employed? (Choose two)
Options
- Amicrozoning
- Bsegmentation
- Cdomain fencing
- Dvirtualization
- Emicroperimeters
How the community answered
(20 responses)- A5% (1)
- B75% (15)
- C15% (3)
- D5% (1)
Why each option
Network segmentation and microperimeters are complementary Zero Trust-aligned design strategies that limit lateral movement and contain damage after an attacker breaches the outer network perimeter.
Microzoning is not a recognized network security design pattern in this context and is not an established architectural approach to protecting internal infrastructure against perimeter breaches.
Segmentation divides the internal network into isolated zones so that an attacker who breaches the perimeter cannot freely traverse the entire network - traffic between segments is controlled and inspected, confining the attacker's reach and directly addressing the scenario where a perimeter breach led to full internal network access.
Domain fencing is not a standard network security design methodology for protecting internal networks after a perimeter compromise.
Virtualization is an infrastructure technology that can support security architectures but does not by itself enforce access controls, segment networks, or prevent lateral movement after a breach.
Microperimeters are a Zero Trust design concept where security boundaries are enforced around individual workloads, applications, or data stores rather than relying solely on the outer perimeter - even after a perimeter breach, each resource requires separate authentication and authorization, preventing the attacker from pivoting freely.
Concept tested: Network segmentation and microperimeter Zero Trust design
Source: https://www.cisco.com/c/en/us/solutions/enterprise/design-zone-security/landing_sba_sec_micro.html
Topics
Community Discussion
No community discussion yet for this question.