Soru

Zorluk: OrtaSecure Network Design and Segmentation

A security architect at a pharmaceutical enterprise is designing the network architecture for a new automated production facility. Match each network design or segmentation technique on the left to its corresponding security application requirement on the right.

  • Air GapIsolating high-risk legacy PLCs by completely disconnecting them from all local and public networks.
  • MicrosegmentationRestricting lateral movement between individual cloud-hosted API microservices using granular host-level policies.
  • Jump ServerProviding a single, hardened entry point for administrative session proxying and auditing into secure database zones.
  • Demilitarized Zone (DMZ)Exposing public-facing web servers while preventing direct incoming connections to internal corporate networks.

Cevap

Air Gap matches with isolating legacy PLCs by completely disconnecting them; Microsegmentation matches with restricting lateral movement between individual cloud microservices; Jump Server matches with providing a hardened administrative proxy entry point; Demilitarized Zone (DMZ) matches with exposing public web servers while isolating the internal network.
Air Gap provides absolute physical isolation for legacy PLCs. Microsegmentation enforces workload-level controls against lateral movement. Jump Server provides a hardened management proxy for database access. DMZ buffers internet-exposed services from internal networks.

Adım Adım Çözüm

1
Identify the extreme isolation requirement for high-risk legacy PLCs.
Complete physical and logical disconnection maps directly to an Air Gap.
Air gapping eliminates all network-based attack vectors by removing physical and logical network connectivity.
2
Analyze the requirement for controlling East-West traffic between cloud microservices.
Granular workload-level policy enforcement maps to Microsegmentation.
Microsegmentation creates fine-grained security zones around individual application components to prevent lateral movement.
3
Evaluate administrative access into internal database segments.
A single proxy entry point for admin sessions maps to a Jump Server.
Jump servers channel, authenticate, and monitor privileged administrative management connections into sensitive internal zones.
4
Determine the perimeter control technique for public web endpoints.
Buffering external services from internal assets maps to a DMZ.
A DMZ isolates internet-facing services on a dedicated subnet separated by firewalls from internal corporate assets.

Anahtar Kavram

Network Design Archetypes and Segmentation Controls
Bu soruyu puanla