After a phishing wave hits enterprise IT, leadership wants to reduce the chance that malware can reach water-plant SCADA. Which mitigation best limits that blast radius?
Select an answer to reveal the explanation.
Short Explanation
Keep the plant network on its own side of the fence. Segmentation stops a phishing mess on office PCs from strolling straight into SCADA—shared flat networks are how small fires become citywide.
Full Explanation
Network segmentation separates high-impact OT/SCADA environments from general enterprise IT so compromise in one zone does not freely propagate. Publishing OT assets, flattening VLANs, or disabling logging increase exposure and reduce visibility rather than mitigating blast radius after phishing.