Soru

Zorluk: OrtaSecure Network Design and Segmentation

A security architect is updating the network architecture for a pharmaceutical company's laboratory. The network contains legacy instrument controllers operating on legacy software alongside modern cloud-connected analytics platforms. The legacy controllers must transmit processed test metrics to an internal staging database, but must be prohibited from initiating connections to the internet or directly communicating with general corporate workstations. Which of the following controls should the security architect implement to enforce isolation while accommodating operational needs? (Select TWO.)

  1. Place legacy controllers on a dedicated VLAN with firewall stateful packet inspection rules restricting East-West traffic exclusively to required ports on the staging database.Cevap
  2. B
    Rely on an upgraded edge boundary firewall to filter inbound traffic while granting implicit trust and unrestricted routing to all internal subnets.
  3. Implement an administrative jump box host configured with multi-factor authentication and role-based access for remote maintenance of the legacy controllers.Cevap
  4. D
    Deploy high-interaction honeypots directly between legacy controllers and the staging server to serve as the inline access control mechanism for data transfers.

Cevap

The correct controls are placing the legacy controllers on a dedicated VLAN with strict East-West firewall rules and deploying an administrative jump box with multi-factor authentication for maintenance access.
Placing legacy lab equipment on a segregated VLAN with restrictive firewall rules enforces microsegmentation and limits East-West network flow exclusively to necessary staging destinations. Pairing this with a jump box ensures administrative management occurs through an audited, multi-factor authenticated transit host rather than direct workstation-to-controller sessions.

Adım Adım Çözüm

1
Analyze the operational requirements and security risks associated with legacy equipment on unsupported systems.
Identified that legacy devices must reach the internal staging database but present high exposure risks if exposed to broader internal or external networks.
Legacy systems lack modern host hardening and patch support, requiring strict network-level isolation.
2
Select network containment and access control mechanisms appropriate for secure architecture design.
Determined that VLAN isolation with firewalled East-West access controls restricts communication pathways, and a jump box secures administrative ingress.
VLAN isolation prevents unauthorized lateral movement while the jump server acts as an audited ingress point for administration.
3
Evaluate and eliminate incorrect architectural control choices.
Rejected edge-only perimeter firewall reliance and inline honeypot deployments.
Edge firewalls do not stop internal lateral movement, and honeypots are deception mechanisms rather than inline traffic filters.

Anahtar Kavram

Secure Network Architecture and East-West Traffic Isolation
Bu soruyu puanla