Soru

Zorluk: OrtaSecure Network Design and Segmentation

A biomedical engineering department at a regional hospital plans to integrate networked smart infusion pumps into the facility's network. To minimize the threat of malware spreading laterally from compromised medical devices to critical electronic health record (EHR) databases while still allowing automated telemetry collection by central servers, which network architecture control should the security team implement?

  1. Place the medical devices into an isolated network segment enforced by firewalls that restrict traffic solely to authorized telemetry collector endpoints.Cevap
  2. B
    Connect the medical devices directly to the internal enterprise subnet while relying on perimeter firewalls to block external malicious traffic.
  3. C
    Implement a complete physical air gap around the medical devices, disconnecting them entirely from all corporate and monitoring networks.
  4. D
    Deploy a passive Network Intrusion Detection System (NIDS) tap as a preventive isolation control between the medical devices and the core network.

Cevap

Place the medical devices into an isolated network segment enforced by firewalls that restrict traffic solely to authorized telemetry collector endpoints.
Placing the medical devices into a dedicated, firewall-enforced network segment (such as a restricted VLAN or microsegment) isolates potentially vulnerable hardware while permitting explicitly defined, unidirectional or limited telemetry traffic to monitoring servers. This enforces the principle of least privilege at the network level and contains lateral threat propagation.

Adım Adım Çözüm

1
Analyze the operational and security requirements
The medical devices require network connectivity for automated telemetry collection, but lateral access to sensitive EHR databases must be strictly prevented.
Security controls must balance operational availability with risk mitigation against lateral movement.
2
Evaluate segmentation strategies
Network segmentation via dedicated VLANs and stateful firewall policies isolates high-risk medical IoT equipment while allowing controlled East-West communications strictly to designated telemetry servers.
Proper zone isolation limits breach blast radiuses and prevents unauthorized lateral network traversal.

Anahtar Kavram

Secure Network Design and Segmentation
Bu soruyu puanla