An organization is updating its network architecture to securely integrate legacy point-of-sale (POS) terminals with a cloud-based inventory system while maintaining PCI DSS compliance. The legacy POS terminals run older operating systems that cannot support endpoint agent installations or host firewalls. Which of the following network segmentation controls should the security team implement to isolate these legacy devices and restrict unnecessary lateral traffic? (Select TWO.)
- Place the legacy POS terminals on a dedicated VLAN with strict East-West access control lists (ACLs) to block terminal-to-terminal traffic.Cevap
- Deploy an inline stateful firewall to enforce explicit North-South traffic controls between the POS segment and the cloud inventory system.Cevap
- CRoute all POS terminal communication directly across the main corporate user subnet to optimize network routing throughput.
- DRely on perimeter edge firewalls for security while maintaining implicit trust across all internal network zones.
Cevap
The security team should isolate the legacy terminals on a dedicated VLAN using East-West access control lists to prevent lateral spread, and implement an inline stateful firewall to enforce explicit North-South filtering for traffic bound for the cloud inventory system.
Isolating legacy systems on a dedicated VLAN with East-West ACL restrictions ensures that individual POS terminals cannot communicate laterally with one another if compromised. Concurrently, an inline stateful firewall enforcing North-South traffic rules restricts outbound traffic strictly to necessary cloud infrastructure connections.
Adım Adım Çözüm
Anahtar Kavram
Secure Network Design and Segmentation