A network architect is designing a new branch office. The branch hosts a public-facing web application, an internal HR portal, and manufacturing control systems (OT). Which segmentation model best reduces lateral movement risk if any one segment is compromised?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because three separate security zones (DMZ, internal, OT) with enforced inter-zone ACLs limit blast radius — compromising the DMZ does not automatically grant access to HR or OT. A is wrong because a flat network allows unrestricted lateral movement once any host is compromised.
Full explanation below image
Full Explanation
B is correct because three separate security zones (DMZ, internal, OT) with enforced inter-zone ACLs limit blast radius — compromising the DMZ does not automatically grant access to HR or OT. A is wrong because a flat network allows unrestricted lateral movement once any host is compromised. C is wrong because co-locating HR and OT creates unnecessary risk to critical infrastructure. D is wrong because direct OT internet exposure violates fundamental ICS security principles.