CISSP Practice Question: A mid-size retailer recently consolidated network controls and stopped enforcing segmentation between…
Correct Answer: A. Increased risk of attacker lateral movement and an expanded breach blast radius
Explanation (CISSP Manager Logic):
Network segmentation is a critical architectural control that enforces containment and the principle of least privilege. Removing these boundaries eliminates the organization's ability to isolate threats, allowing a minor compromise to escalate into a catastrophic enterprise-wide breach.
By maintaining network segmentation, you:
- Limit the blast radius of security incidents to a single zone.
- Ensure compliance with regulatory mandates like PCI DSS.
- Improve detection capabilities by monitoring inter-zone traffic.
While the other options are relevant, they fall short because:
- B: Prioritizing data sharing over security controls introduces unacceptable risk to sensitive payment assets.
- C: Reduced administrative overhead is an operational convenience that does not justify the loss of risk mitigation.
- D: Minor performance gains are negligible compared to the high cost of a potential data breach.
Think like a manager:
Security architecture must prioritize risk containment over operational ease. Managers must view segmentation as a strategic defense-in-depth requirement to protect the organization's most valuable assets.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial