A public health clinic’s IoT WLAN segment must not reach electronic health record (EHR) servers. Which control best limits that lateral movement?
Select an answer to reveal the explanation.
Short Explanation
IoT gadgets and EHR servers should not be pen pals. An ACL that denies IoT VLAN traffic to EHR networks blocks that lateral hop. Louder SSIDs and paper logs are not network segmentation.
Full Explanation
ACLs that deny traffic from an IoT WLAN VLAN to EHR server networks limit lateral movement from lower-trust medical devices into sensitive clinical systems. This wired enforcement complements wireless segmentation for regulated healthcare environments. RF branding changes, DHCP quirks, or physical logs do not replace Layer-3/4 deny policy between those segments.