Case 5D6CA7 · Network · L1 Foundations
Network Segmentation
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Segmentation splits the network into zones (VLANs, subnets, VPCs) with enforced policy between them
- Goal is limiting blast radius: a compromised workstation should not reach domain controllers or OT directly
- Enforce with ACLs and firewalls at zone boundaries; a VLAN alone is not a security control without filtering
- Microsegmentation applies per-workload policy (host firewalls, SDN) for east-west traffic
- Validate with flow logs and reachability testing; flat networks are a common ransomware amplifier
If the interviewer pushes back
- How would you segment a hospital network where medical devices cannot run agents?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.