Soru

Zorluk: OrtaSecure Network Design and Segmentation

A security engineer is redesigning the network architecture for an automated logistics center. The facility incorporates smart building controllers (HVAC, environmental sensors, and smart lighting) that must continuously transmit status metrics outbound to a cloud management service. However, corporate compliance requires that these controllers must be strictly prohibited from initiating connection requests to the internal database servers or corporate workstations hosting sensitive supply chain data. Which of the following network architecture strategies best fulfills these requirements while reducing lateral movement risk?

  1. Place smart building controllers into a dedicated microsegmented VLAN with firewall policies permitting restricted outbound traffic to the cloud service while blocking East-West traffic to internal corporate zones.Cevap
  2. B
    Consolidate smart building controllers and corporate databases on a unified internal network segment protected by a single perimeter next-generation firewall.
  3. C
    Completely air-gap the smart building controller network from all internal and external networks, relying on daily manual USB data exports for cloud analytics.
  4. D
    Deploy a passive network intrusion detection system (IDS) at the switch core to block unauthorized connection attempts originating from the smart building controllers.

Cevap

Place smart building controllers into a dedicated microsegmented VLAN with firewall policies permitting restricted outbound traffic to the cloud service while blocking East-West traffic to internal corporate zones.
Placing smart controllers into a microsegmented VLAN with specific firewall egress rules satisfies both requirements: it allows outbound telemetry to the vendor's cloud service while preventing lateral (East-West) traffic to internal database servers and corporate workstations.

Adım Adım Çözüm

1
Analyze the operational and security requirements
Smart sensors require outbound (North-South) cloud communication, but must be prevented from connecting laterally (East-West) to internal enterprise assets.
Segmenting IoT and smart infrastructure limits breach blast radiuses while maintaining necessary operational connectivity.
2
Evaluate network isolation and traffic control options
Microsegmentation creates granular security boundaries around device classes, enforcing access policies that allow outbound cloud traffic while denying internal cross-zone connection requests.
Proper secure network design enforces Zero Trust principles by restricting lateral movement between distinct security tiers.

Anahtar Kavram

Network Microsegmentation and East-West Traffic Isolation
Bu soruyu puanla