Soru

Zorluk: OrtaSecure Network Design and Segmentation

An industrial manufacturing facility needs to secure its operational technology (OT) network housing Programmable Logic Controllers (PLCs) from the corporate IT network. Unauthorized network scanning originating from corporate workstations recently reached the shop floor. The security architect must permit authorized engineering personnel to conduct remote maintenance on PLCs while preventing direct network routing between IT endpoints and OT devices. Which of the following network architecture designs best meets these security requirements?

  1. A
    Place the PLCs and corporate engineering workstations on the same VLAN to eliminate routing overhead during maintenance operations.
  2. Deploy a jump box in a segmented DMZ requiring multifactor authentication and session recording for management traffic between IT and OT networks.Cevap
  3. C
    Rely on an edge perimeter firewall between the corporate WAN and OT network while permitting unrestricted internal routing across internal subnets.
  4. D
    Configure an inline honeypot within the OT network to act as a detective control that actively drops incoming SSH traffic targeting PLCs.

Cevap

Deploying a jump box in a segmented DMZ requiring multifactor authentication and session recording for management traffic between IT and OT networks.
Deploying a jump box within a demilitarized zone (DMZ) between corporate IT and industrial control OT networks prevents direct network connectivity between endpoints. Requiring strong authentication and session logging ensures remote maintenance traffic is securely managed, authorized, and audited without exposing PLCs directly to enterprise network risks.

Adım Adım Çözüm

1
Analyze the operational and security requirements
Direct IP routing between corporate IT workstations and OT PLCs must be blocked while still enabling monitored administrative access.
Protecting critical industrial control devices against unauthorized lateral movement and network scanning requires strict security zone separation.
2
Evaluate secure network boundary and transit control options
A jump box situated in a DMZ isolates the two zones by terminating incoming sessions and proxying management commands rather than allowing direct end-to-end packet transit.
Intermediary jump servers combined with MFA and session auditing enforce least-privilege access and strong zone isolation.
3
Verify the correct architectural implementation
The DMZ jump box architecture fulfills segmentation principles for OT and IT network isolation.
It prevents direct network traversal between environments while maintaining full auditability for remote administration.

Anahtar Kavram

Secure Network Design and Segmentation using DMZ and Jump Servers
Tahmini Süre:1m 30s
Bu soruyu puanla