From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Network segmentation

Network segmentation

- When building the architecture of our enterprise networks, we should consider how to utilize network segmentation to increase our security. We may achieve this segmentation by using access control lists, virtual local area networks, or even physical routers, switches, and firewalls. Many organizations will create zones or segments for different trust levels throughout their networks. The three most common zones are the internal or trusted zone, the external or untrusted zone, and the demilitarized zone which is the semi-trusted zone. In large organizations, there may be additional segments or zones created inside of these three larger zones as well. For example, in the internal zone, there may be a segment for users, another for the data center, and another for all of our systems involved with taking credit card payments. By segmenting out into zones, we can individually apply more granular security controls to each of these individually. Because we often create these segments or…

Contents