Soru

Zorluk: OrtaSecure Network Design and Segmentation

A university network engineering team is designing an architecture to secure a high-containment biomedical research laboratory. The lab contains unpatchable legacy telemetry devices that must transmit real-time experimental data to an on-premises database in the core enterprise data center, but must be prohibited from initiating or receiving any other traffic across the campus network or the internet. Which of the following network design configurations best achieves this isolation while mitigating lateral movement risks?

  1. Place the legacy devices on an isolated VLAN bounded by strict firewall policies that permit only outbound, single-port East-West traffic destined for the specific database IP address.Cevap
  2. B
    Position all legacy laboratory devices inside a traditional perimeter DMZ to inspect incoming North-South traffic from external campus networks.
  3. C
    Connect the legacy devices directly to the core data center subnet and deploy host-based intrusion detection agents onto each unpatchable operating system.
  4. D
    Configure dual-homed network interface cards on the legacy workstations to directly bridge the research lab network segment with the enterprise management network.

Cevap

Placing the legacy devices on an isolated VLAN bounded by strict firewall policies that permit only outbound, single-port East-West traffic destined for the specific database IP address.
The correct option applies proper network segmentation principles by establishing an isolated VLAN for vulnerable legacy devices and restricting internal East-West traffic using strict firewall ACLs. Limiting communications exclusively to the database server IP and designated port enforces least privilege network access and blocks lateral movement.

Adım Adım Çözüm

1
Analyze network isolation requirements for unpatchable legacy devices
Identified that legacy systems present high vulnerability risk and require strict restriction of network pathways.
Unpatchable endpoints cannot defend against modern exploits and must be restricted to minimal required functionality.
2
Evaluate traffic vector directionality and scope
Traffic flow is internal node-to-internal server (East-West traffic) requiring restricted destination and port enforcement.
North-South perimeter controls do not regulate traffic flowing between internal subnets or zones.
3
Select optimal segmentation topology
Isolated VLAN with explicit stateful firewall rules restricting all non-essential East-West communication.
Prevents unauthorized lateral movement across internal enterprise subnets while enabling necessary telemetry transmission.

Anahtar Kavram

Network Segmentation and East-West Traffic Filtering
Tahmini Süre:1m 30s
Bu soruyu puanla