A network administrator needs to isolate legacy industrial control devices that cannot accept software patches from the primary corporate network to prevent unauthorized lateral movement. Which of the following network design techniques best fulfills this security requirement?
- Placing the legacy devices into a dedicated isolated VLAN with strict firewall access control lists restricting inter-zone communicationAnswer
- BPlacing the legacy devices on the main internal network segment while depending entirely on the perimeter firewall to inspect incoming internet traffic
- CDeploying host-based endpoint security agents on the legacy devices while keeping them on the general workstation subnet
- DConnecting the legacy devices directly to the core network router with dynamic routing enabled to increase throughput
Answer
Placing the legacy devices into a dedicated isolated VLAN with strict firewall access control lists restricting inter-zone communication
Placing legacy devices into a dedicated, isolated VLAN enforced by firewall rules restricts network traffic to only authorized communication paths, preventing lateral threat movement across the internal network.
Step-by-Step Solution
Key Concept
Network Segmentation and Isolation
Estimated Time:45s