Soru

Zorluk: OrtaSecure Network Design and Segmentation

An enterprise automated distribution center utilizes networked Industrial Internet of Things (IIoT) controllers for material handling equipment. The security architecture team must enable the corporate enterprise resource planning (ERP) platform to exchange telemetry and commands with the IIoT controllers while preventing compromised IIoT devices from traversing laterally into corporate endpoints. Which of the following network design controls should the security team implement? (Select TWO.)

  1. Place IIoT controllers into a dedicated microsegmented network zone governed by strict East-West access control policies.Cevap
  2. Deploy an inline Next-Generation Firewall (NGFW) performing stateful protocol inspection between the corporate ERP network and the IIoT zone.Cevap
  3. C
    Interconnect IIoT access switches directly to the corporate core switch via unmanaged trunking while relying on host-based firewalls for network isolation.
  4. D
    Designate the IIoT network subnet as an internal trusted zone within the perimeter firewall to optimize network throughput.

Cevap

The security team should implement dedicated microsegmentation for IIoT devices with East-West access policies, and deploy an inline Next-Generation Firewall (NGFW) performing stateful protocol inspection between the corporate ERP network and the IIoT zone.
Placing IIoT controllers into a microsegmented zone enforces strict East-West control policies, preventing unauthorized lateral movement if one device is breached. Deploying an inline Next-Generation Firewall (NGFW) between the corporate ERP network and the IIoT zone ensures rigorous stateful North-South inspection and protocol filtering across boundary zones.

Adım Adım Çözüm

1
Identify the primary traffic flows and risks
North-South traffic flows between ERP and IIoT; East-West traffic flows between individual IIoT controllers.
Isolation requires distinct controls for lateral movement and zone-boundary transit.
2
Select intra-zone isolation mechanism
Microsegmentation with granular access control policies.
Prevents compromised IIoT endpoints from pivoting to neighboring controllers.
3
Select inter-zone perimeter enforcement mechanism
Inline Next-Generation Firewall (NGFW) with deep packet inspection.
Ensures stateful inspection and validation of telemetry/command protocols traversing between corporate and IIoT zones.

Anahtar Kavram

Secure Network Design and Microsegmentation
Bu soruyu puanla