Soru

Zorluk: ZorSecure Network Design and Segmentation

A fintech enterprise is redesigning its cloud-native payment gateway architecture to achieve PCI-DSS compliance. The security architecture must restrict lateral movement between individual microservices inside the cardholder data environment (CDE), enforce strict inline policy inspection for outbound internet-bound management connections, and eliminate reliance on internal network location trust. Which of the following network architecture controls should the security team implement to satisfy these requirements? (Select TWO.)

  1. Implement microsegmentation using software-defined networking (SDN) policies to enforce granular East-West traffic filtering between workloads.Cevap
  2. Deploy an inline Next-Generation Firewall (NGFW) at the egress boundary to inspect and filter North-South outbound management traffic.Cevap
  3. C
    Consolidate all CDE microservices into a single flat VLAN to simplify passive network intrusion detection system (NIDS) monitoring.
  4. D
    Configure core router access control lists (ACLs) to grant implicit trust to any traffic originating from internal administrative IP subnets.

Cevap

The security team should implement microsegmentation via SDN policies to restrict East-West workload communication and deploy an inline NGFW at the egress boundary for North-South traffic inspection.
Microsegmentation enables fine-grained policy enforcement at the individual workload level, effectively isolating systems and blocking East-West lateral movement inside the cardholder data environment. Deploying an inline NGFW at the perimeter boundary ensures all outbound (North-South) management traffic undergoes application-aware inspection and threat prevention prior to egressing.

Adım Adım Çözüm

1
Evaluate internal workload isolation requirements for lateral movement prevention.
Microsegmentation leverages software-defined controls to isolate workloads at the granular container or host interface level.
Traditional network boundaries (VLANs) do not prevent lateral movement between hosts on the same subnet, whereas microsegmentation enforces granular rules on East-West traffic.
2
Evaluate egress network boundary inspection requirements.
An inline Next-Generation Firewall (NGFW) monitors and inspects North-South traffic crossing the perimeter.
Egress filtering with application-layer awareness ensures outbound sessions to external services adhere to compliance policies and prevents unauthorized data exfiltration.

Anahtar Kavram

Secure Network Design, Microsegmentation, and Egress Boundary Filtering
Bu soruyu puanla