Soru

Zorluk: OrtaSecure Network Design and Segmentation

A retail chain is redesigning its store network architecture to satisfy payment card industry compliance requirements. Each store location operates on-site Point-of-Sale (POS) terminals connected to a shared local switch alongside store manager workstations and guest access points. To minimize audit scope and prevent lateral threat movement if a single terminal is compromised, POS terminals must be blocked from communicating directly with one another on the local switch while retaining full access to the router default gateway for transaction processing. Which network design control should the security engineer implement on the local switch?

  1. Private VLANs (PVLANs) with POS terminals configured on isolated ports and the router connected to a promiscuous portCevap
  2. B
    A physical air gap separating the local POS network switch completely from all upstream routers and central systems
  3. C
    A perimeter firewall configured to inspect and filter incoming internet traffic at the store WAN boundary
  4. D
    A deception honeypot deployed inline within the POS subnet to drop unauthorized intra-VLAN packets

Cevap

Private VLANs (PVLANs) with POS terminals configured on isolated ports and the router connected to a promiscuous port
Private VLANs (PVLANs) provide Layer 2 isolation within the same IP subnet. Configuring POS terminal ports as isolated ports ensures that frames sent between POS terminals are blocked at the switch layer. Configuring the router connection on a promiscuous port enables all isolated ports to communicate upstream with the default gateway for transaction processing.

Adım Adım Çözüm

1
Analyze the technical requirement and isolation boundary
POS terminals reside on the same Layer 2 switch segment but must be prevented from sending East-West traffic to one another while continuing to send North-South traffic to the gateway.
Restricting lateral movement inside a shared subnet limits malware spread and reduces compliance audit boundaries.
2
Evaluate Layer 2 microsegmentation capabilities
Private VLANs (PVLANs) partition a VLAN into primary and secondary domains, providing granular port-level isolation without requiring separate subnets per host.
Isolated ports drop all frames directed to other isolated ports, forwarding traffic only to designated promiscuous ports.
3
Select the correct switch configuration
Assign POS switch ports as isolated ports and the default gateway router port as a promiscuous port.
This setup allows terminals to reach external payment networks via the gateway while completely blocking intra-VLAN communication.

Anahtar Kavram

Private VLAN (PVLAN) Microsegmentation
Tahmini Süre:1m 30s
Bu soruyu puanla