700-846 · Question #5
How can threats in surface areas be reduced?
The correct answer is B. flat networks. There appears to be an error in the provided answer key. Option B (flat networks) is actually incorrect from a cybersecurity standpoint - flat networks increase attack surface risk by allowing unrestricted lateral movement once an attacker gains entry. The correct answer is A…
Question
How can threats in surface areas be reduced?
Options
- Aeffective network segmentation
- Bflat networks
- Cdevise visibility
- Dscalability
How the community answered
(24 responses)- B92% (22)
- C4% (1)
- D4% (1)
Explanation
There appears to be an error in the provided answer key. Option B (flat networks) is actually incorrect from a cybersecurity standpoint - flat networks increase attack surface risk by allowing unrestricted lateral movement once an attacker gains entry.
The correct answer is A - effective network segmentation.
Network segmentation divides a network into isolated zones, so that a compromise in one segment cannot easily spread to others. This directly reduces the attack surface by limiting an attacker's reach and containing potential breaches within smaller, controlled boundaries.
Why the other options are wrong:
- B. Flat networks - the opposite of the right answer; a flat network gives any connected device access to all others, maximizing exposure
- C. Device visibility - knowing what's on your network (asset inventory) is a security best practice, but visibility alone doesn't reduce the surface area
- D. Scalability - this refers to a system's ability to grow/handle load; it's an architectural concern, not a threat-reduction strategy
Memory tip: Think of segmentation like compartments in a submarine - if one floods, the others stay sealed. "Segment to contain" is your mantra for attack surface reduction questions.
Recommendation: Double-check your source material or exam prep guide, as the answer key appears to have a typo - B and A may have been swapped.
Topics
Community Discussion
No community discussion yet for this question.