CISSP · Question #1199
A systems engineer is designing a wide area network (WAN) environment for a new organization. The WAN will connect sites holding information at various levels of sensitivity, from publicly available…
The correct answer is D. Align risk across all interconnected elements to ensure critical threats are detected and handled. When designing a WAN that connects sites with varying data sensitivity levels and requires high interconnectedness, the best approach is to align risk management across all interconnected elements rather than focusing solely on perimeter or isolation controls.
Question
A systems engineer is designing a wide area network (WAN) environment for a new organization. The WAN will connect sites holding information at various levels of sensitivity, from publicly available to highly confidential. The organization requires a high degree of interconnectedness to support existing business processes. What is the BEST design approach to securing this environment?
Options
- APlace firewalls around critical devices, isolating them from the rest of the environment.
- BLayer multiple detective and preventative technologies at the environment perimeter.
- CUse reverse proxies to create a secondary "shadow" environment for critical systems.
- DAlign risk across all interconnected elements to ensure critical threats are detected and handled.
How the community answered
(31 responses)- A13% (4)
- B6% (2)
- C23% (7)
- D58% (18)
Why each option
When designing a WAN that connects sites with varying data sensitivity levels and requires high interconnectedness, the best approach is to align risk management across all interconnected elements rather than focusing solely on perimeter or isolation controls.
Placing firewalls only around critical devices creates isolated islands of protection but ignores lateral movement threats and the interconnectedness requirement, leaving gaps between segments of varying sensitivity.
Layering technologies solely at the environment perimeter is a traditional perimeter-centric model that fails in a highly interconnected WAN where threats can originate from internal sites or traverse trusted inter-site links without crossing the external perimeter.
Reverse proxies and shadow environments are application-layer techniques designed for web-facing service protection, not for securing a multi-site WAN carrying data of varying classification levels across diverse business processes.
Aligning risk across all interconnected elements reflects a holistic, defense-in-depth security architecture that accounts for the reality that highly interconnected environments cannot rely on a single control boundary. By ensuring that risk assessments, threat detection, and response capabilities are consistently applied to every node and link in the WAN, critical threats can be identified and mitigated regardless of where they originate. This approach directly addresses the challenge of mixed-sensitivity sites sharing a common network fabric.
Concept tested: WAN security design with risk-aligned defense-in-depth
Source: https://learn.microsoft.com/en-us/azure/well-architected/security/design-network
Topics
Community Discussion
No community discussion yet for this question.