An enterprise facility contains legacy operational technology (OT) devices that cannot receive security updates or support modern encryption protocols. Which network design approach provides the most complete protection by physically isolating these critical devices from all untrusted and corporate network traffic?
- Establishing an air-gapped network segment that has no physical or logical interface connections to external networksAnswer
- BPlacing the legacy devices on the main internal local area network while relying on a perimeter firewall for protection
- CDeploying a network intrusion detection system at the main internet boundary to block malicious traffic heading toward OT devices
- DMaintaining a flat network architecture while assigning separate IP subnet addresses without VLAN enforcement
Answer
Establishing an air-gapped network segment that has no physical or logical interface connections to external networks is the correct choice.
Air-gapping ensures that a network segment is physically and logically disconnected from all other networks, including internal corporate networks and the internet. For legacy OT equipment that cannot be patched or secured via software, air-gapping provides the strongest possible boundary control.
Step-by-Step Solution
Key Concept
Air-gapping and Network Isolation