Soru

Zorluk: OrtaSecure Network Design and Segmentation

A municipal water utility is designing a network architecture to allow its corporate analytics platform to pull daily operational telemetry logs from a Supervisory Control and Data Acquisition (SCADA) server located inside a high-security Operational Technology (OT) zone. The organization's security policy strictly forbids any inbound network connections into the SCADA zone and prohibits direct bi-directional TCP/IP session establishment between the corporate network and the OT environment. Which of the following network architecture controls best fulfills these requirements?

  1. Deploy a unidirectional gateway (data diode) that physically enforces one-way hardware data transmission from the SCADA zone to a historian server in the corporate DMZ.Cevap
  2. B
    Configure an internal stateful firewall to allow inbound TLS-encrypted traffic from the corporate analytics server to the SCADA server on a dedicated port.
  3. C
    Implement an isolated 802.1Q virtual LAN (VLAN) containing both corporate analytics and SCADA servers, restricting traffic using router Access Control Lists (ACLs).
  4. D
    Position a dual-homed jump box in the DMZ that requires multi-factor authentication before bridging interactive RDP sessions into the SCADA headend.

Cevap

Deploy a unidirectional gateway (data diode) that physically enforces one-way hardware data transmission from the SCADA zone to a historian server in the corporate DMZ.
Deploying a unidirectional gateway (data diode) physically enforces one-way data flow using optical emitters and receivers. This guarantees that SCADA telemetry can be sent to an enterprise DMZ server without allowing any inbound electrical signals or network connection requests back into the SCADA network.

Adım Adım Çözüm

1
Analyze the security constraints specified in the scenario.
Identified two strict rules: zero inbound network connections permitted into the OT/SCADA zone, and no bi-directional TCP/IP sessions allowed between IT and OT.
Security controls must enforce absolute traffic directionality to protect critical infrastructure OT environments from corporate network compromise.
2
Evaluate potential network segmentation technologies against the constraints.
Standard firewalls, VLAN ACLs, and jump boxes all rely on software logic or enable bi-directional TCP handshakes, allowing potential inbound requests.
Only hardware-enforced unidirectional transmission (data diodes) physically prevents optical or electrical signal propagation in the reverse direction.
3
Select the optimal control mechanism.
A unidirectional gateway (data diode) transmitting SCADA telemetry outbound to a corporate DMZ historian server satisfies all requirements.
This architecture allows external systems to consume telemetry without exposing the SCADA network to inbound connection attempts.

Anahtar Kavram

Unidirectional Data Diodes and OT/ICS Segmentation
Bu soruyu puanla