GSEC · Question #1
Your organization has broken its network into several sections/segments, which are separated by firewalls, ACLs and VLANs. The purpose is to defend segments of the network from potential attacks that
The correct answer is B. Protected enclaves. Network segmentation using firewalls, ACLs, and VLANs to isolate sections from each other is the 'protected enclaves' defense-in-depth strategy.
Question
Your organization has broken its network into several sections/segments, which are separated by firewalls, ACLs and VLANs. The purpose is to defend segments of the network from potential attacks that originate in a different segment or that attempt to spread across segments. This style of defense-in-depth protection is best described as which of the following?
Options
- AUniform protection
- BProtected enclaves
- CVector-oriented
- DInformation-centric
How the community answered
(31 responses)- A3% (1)
- B74% (23)
- C16% (5)
- D6% (2)
Why each option
Network segmentation using firewalls, ACLs, and VLANs to isolate sections from each other is the 'protected enclaves' defense-in-depth strategy.
Uniform protection applies identical security controls to all devices without segmentation, which is the opposite of dividing the network into separately defended zones.
Protected enclaves is a defense-in-depth approach where the network is divided into isolated segments, each bounded by access controls such as firewalls, ACLs, and VLANs. This model assumes threats can originate within any segment and focuses on limiting lateral movement between zones. The goal is to contain breaches so that a compromise in one enclave does not automatically spread to others.
Vector-oriented protection focuses security resources on specific attack pathways or threat vectors rather than on isolating network segments from each other.
Information-centric protection concentrates controls around specific high-value data assets rather than around network boundary segments as a whole.
Concept tested: Defense-in-depth protected enclaves network segmentation
Source: https://csrc.nist.gov/publications/detail/sp/800-27/rev-a/final
Topics
Community Discussion
No community discussion yet for this question.