nerdexam
Cisco

400-007 · Question #387

In the wake of a security compromise incident where the internal networks were breached by an outside attacker at the perimeter of the infrastructure, an enterprise is now evaluating potential…

The correct answer is B. segmentation E. microperimeters. Network segmentation and microperimeters are complementary Zero Trust-aligned design strategies that limit lateral movement and contain damage after an attacker breaches the outer network perimeter.

Designing Security

Question

In the wake of a security compromise incident where the internal networks were breached by an outside attacker at the perimeter of the infrastructure, an enterprise is now evaluating potential measures that can help protect against the same type of incident in the future. What are two design options that can be employed? (Choose two)

Options

  • Amicrozoning
  • Bsegmentation
  • Cdomain fencing
  • Dvirtualization
  • Emicroperimeters

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    75% (15)
  • C
    15% (3)
  • D
    5% (1)

Why each option

Network segmentation and microperimeters are complementary Zero Trust-aligned design strategies that limit lateral movement and contain damage after an attacker breaches the outer network perimeter.

Amicrozoning

Microzoning is not a recognized network security design pattern in this context and is not an established architectural approach to protecting internal infrastructure against perimeter breaches.

BsegmentationCorrect

Segmentation divides the internal network into isolated zones so that an attacker who breaches the perimeter cannot freely traverse the entire network - traffic between segments is controlled and inspected, confining the attacker's reach and directly addressing the scenario where a perimeter breach led to full internal network access.

Cdomain fencing

Domain fencing is not a standard network security design methodology for protecting internal networks after a perimeter compromise.

Dvirtualization

Virtualization is an infrastructure technology that can support security architectures but does not by itself enforce access controls, segment networks, or prevent lateral movement after a breach.

EmicroperimetersCorrect

Microperimeters are a Zero Trust design concept where security boundaries are enforced around individual workloads, applications, or data stores rather than relying solely on the outer perimeter - even after a perimeter breach, each resource requires separate authentication and authorization, preventing the attacker from pivoting freely.

Concept tested: Network segmentation and microperimeter Zero Trust design

Source: https://www.cisco.com/c/en/us/solutions/enterprise/design-zone-security/landing_sba_sec_micro.html

Topics

#network segmentation#microperimeters#perimeter security#breach mitigation

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice