Segmentation, Firewalls, and Zero Trust
- Explain network access policy and containment
- Apply the idea to evidence from a realistic technology scenario
- Justify a decision using security, reliability, cost, and user impact
Segmentation, Firewalls, and Zero Trust
Segmentation separates trust zones; firewalls enforce permitted flows; zero-trust design continuously evaluates identity, device, context, and least privilege rather than trusting traffic merely because it is “inside.” Default-deny policy allows documented business needs.
Decision lens
Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.
A guest wireless client can directly connect to printers, cameras, and finance servers.
- 1.The guest zone lacks effective isolation.
- 2.Inventory which destinations and services guests genuinely need.
- 3.Deny guest-to-internal traffic and allow internet access through controlled services.
- 4.Validate the rule set and monitor denied attempts.
What does default deny mean?
Which response best demonstrates complete reasoning about network access policy and containment?
For a scenario about network access policy and containment, identify the decisive evidence before naming a response. A defensible conclusion here is: Create a distinct guest segment with default-deny access to internal resources.
Answer the 2 checkpoints as you read.
Sign in to save your progress