Soru

Zorluk: OrtaSecure Network Design and Segmentation

A healthcare organization must connect legacy diagnostic imaging equipment running unsupported operating systems to the enterprise network. The architecture must allow authorized workstations to retrieve image files while preventing lateral movement if an imaging system is compromised, and restricting administrative access to authenticated technicians. Which of the following network design strategies best fulfills these security requirements?

  1. Isolate the diagnostic equipment on a dedicated VLAN with strict East-West firewall rules and require administrative management to occur through a secure jump host.Cevap
  2. B
    Place the diagnostic equipment in the public-facing DMZ alongside external web services to ensure all traffic passes through the perimeter firewall.
  3. C
    Maintain a flat internal network topology relying on the edge firewall to filter external threats while preserving high internal data transfer speeds.
  4. D
    Deploy an inline honeypot inside the diagnostic subnet to automatically block lateral network scans directed at the primary database.

Cevap

Isolate the diagnostic equipment on a dedicated VLAN with strict East-West firewall rules and require administrative management to occur through a secure jump host.
Isolating legacy hardware on a dedicated VLAN with East-West firewall rules restricts lateral movement across internal zones, while requiring access via a jump host ensures administrative traffic is authenticated, monitored, and controlled.

Adım Adım Çözüm

1
Analyze the threat profile of legacy biomedical equipment.
Identify that unsupported legacy operating systems present unpatchable vulnerability risks and require network-level containment.
Unmitigated vulnerabilities on legacy systems make them high-risk targets for compromise and lateral movement.
2
Evaluate internal network traffic control mechanisms.
Determine that East-West firewall policy enforcement and VLAN segmentation are required between internal subnets.
Perimeter firewalls only inspect North-South traffic and cannot prevent lateral movement between internal zones.
3
Establish secure administrative access controls.
Require management traffic to traverse a bastion host / jump server with multifactor authentication and session logging.
Direct management sessions from general user subnets to sensitive isolated zones introduce severe security risks.

Anahtar Kavram

Network Segmentation and East-West Traffic Isolation
Bu soruyu puanla