A SOC analyst sees EDR alerts showing compromised IaaS application servers attempting SMB and RDP to adjacent servers and domain controllers. The environment uses a perimeter firewall and VLANs, but traffic between internal workloads remains broad. Which architecture control should the analyst recommend to limit east-west lateral movement between workloads?
Select an answer to reveal the explanation.
Short Explanation
Think of east-west traffic like doors between rooms in your building; if one room's compromised, you don't want every door open. Microsegmentation puts locks between workloads so lateral movement stops at the next room, not just at the front door. The trap is picking a perimeter or NAT fix when the problem is already inside.
Full Explanation
Microsegmentation applies policy at the identity or workload boundary, allowing only expected application-to-application traffic inside the data center or cloud. In a hybrid estate, perimeter firewalls inspect north-south flows and VLANs separate broad zones, but neither prevents a compromised host from reaching adjacent servers inside the same zone. Least-privilege east-west rules between application servers, domain controllers, and databases reduce lateral movement and make anomalous internal connections visible in EDR or NetFlow. A north-south firewall policy controls ingress and egress at network edges, so it does not stop already-internal hosts from contacting other internal hosts. A DMZ web server placement isolates externally facing services from internal systems, but it does not regulate traffic between two internal IaaS workloads. Network address translation hides internal addressing and supports egress mapping, but it is not a least-privilege control for server-to-server lateral movement. Exam caveat: choose microsegmentation when the scenario emphasizes east-west traffic, workload-to-workload policy, or lateral movement after initial compromise. Operational check: map critical application flows, then define allow-list rules between workload identities before moving east-west traffic to deny-by-default.