A defensible network architecture principle states that adversaries must traverse known, controlled paths. Which control most directly enforces this for internal lateral movement?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because internal segmentation with firewall choke points forces lateral movement attempts through controlled inspection points, allowing detection and blocking. A is wrong because perimeter firewalls only address north-south traffic from the internet.
Full explanation below image
Full Explanation
B is correct because internal segmentation with firewall choke points forces lateral movement attempts through controlled inspection points, allowing detection and blocking. A is wrong because perimeter firewalls only address north-south traffic from the internet. C is wrong because HTTPS enforcement is an application-layer control that does not restrict network paths. D is wrong because MFA controls authentication, not network traversal paths between segments.