An enterprise automated distribution center utilizes networked Industrial Internet of Things (IIoT) controllers for material handling equipment. The security architecture team must enable the corporate enterprise resource planning (ERP) platform to exchange telemetry and commands with the IIoT controllers while preventing compromised IIoT devices from traversing laterally into corporate endpoints. Which of the following network design controls should the security team implement? (Select TWO.)
- Place IIoT controllers into a dedicated microsegmented network zone governed by strict East-West access control policies.Cevap
- Deploy an inline Next-Generation Firewall (NGFW) performing stateful protocol inspection between the corporate ERP network and the IIoT zone.Cevap
- CInterconnect IIoT access switches directly to the corporate core switch via unmanaged trunking while relying on host-based firewalls for network isolation.
- DDesignate the IIoT network subnet as an internal trusted zone within the perimeter firewall to optimize network throughput.
Cevap
The security team should implement dedicated microsegmentation for IIoT devices with East-West access policies, and deploy an inline Next-Generation Firewall (NGFW) performing stateful protocol inspection between the corporate ERP network and the IIoT zone.
Placing IIoT controllers into a microsegmented zone enforces strict East-West control policies, preventing unauthorized lateral movement if one device is breached. Deploying an inline Next-Generation Firewall (NGFW) between the corporate ERP network and the IIoT zone ensures rigorous stateful North-South inspection and protocol filtering across boundary zones.
Adım Adım Çözüm
Anahtar Kavram
Secure Network Design and Microsegmentation