Soru

Zorluk: OrtaSecure Network Design and Segmentation

A financial services organization maintains an on-premises datacenter hosting a critical legacy mainframe database and a public cloud environment running web microservices. The organization must allow cloud microservices to query specific API endpoints on the mainframe without exposing the mainframe's on-premises subnet to the entire cloud Virtual Private Cloud (VPC) and without allowing lateral East-West traffic if a cloud service is compromised. Which secure network design approach best achieves this requirement?

  1. Configuring private endpoint services to publish only the specific mainframe API interface directly into the cloud VPC via dedicated virtual private connections.Cevap
  2. B
    Establishing a standard site-to-site IPsec VPN tunnel with full routing between all cloud VPC subnets and the legacy mainframe local area network.
  3. C
    Relocating the legacy mainframe database into a public perimeter network (DMZ) protected solely by perimeter firewall access control lists.
  4. D
    Implementing an air-gapped network segment around the mainframe and relying on scheduled batch exports transmitted via physical storage media.

Cevap

Configuring private endpoint services to publish only the specific mainframe API interface directly into the cloud VPC via dedicated virtual private connections.
Publishing the mainframe API through private endpoint technology provides granular service-level microsegmentation. It enables cloud microservices to interact exclusively with the designated API interface over a private connection without exposing the surrounding internal network or granting routing access to other on-premises systems.

Adım Adım Çözüm

1
Analyze the access requirement between cloud microservices and the legacy mainframe.
Real-time API access is required, but network exposure must be strictly limited to the targeted service.
Broad subnet-to-subnet connectivity increases attack surface and lateral movement risks.
2
Evaluate segmentation mechanisms for hybrid cloud connectivity.
Private endpoints (such as Cloud PrivateLink) map a specific service endpoint to a private IP within the VPC without creating a full network route.
This enforces microsegmentation by isolating network access strictly to the required application port and interface.

Anahtar Kavram

Hybrid Cloud Microsegmentation and Private Endpoints
Tahmini Süre:1m 15s
Bu soruyu puanla