A network administrator needs to isolate legacy industrial control devices that cannot accept software patches from the primary corporate network to prevent unauthorized lateral movement. Which of the following network design techniques best fulfills this security requirement?
- Placing the legacy devices into a dedicated isolated VLAN with strict firewall access control lists restricting inter-zone communicationCevap
- BPlacing the legacy devices on the main internal network segment while depending entirely on the perimeter firewall to inspect incoming internet traffic
- CDeploying host-based endpoint security agents on the legacy devices while keeping them on the general workstation subnet
- DConnecting the legacy devices directly to the core network router with dynamic routing enabled to increase throughput
Cevap
Placing the legacy devices into a dedicated isolated VLAN with strict firewall access control lists restricting inter-zone communication
Placing legacy devices into a dedicated, isolated VLAN enforced by firewall rules restricts network traffic to only authorized communication paths, preventing lateral threat movement across the internal network.
Adım Adım Çözüm
Anahtar Kavram
Network Segmentation and Isolation
Tahmini Süre:45s