AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/3/3-3)
Unit 3 · Topic 3.3
3.3 Protecting Networks: Segmentation
Segmentation splits one big network into smaller isolated pieces, so an adversary who breaks into one piece can't easily reach the rest. This topic covers the three main ways to segment (subnets, VLANs and a screened subnet, or DMZ) and why segmentation lets you give each part its own level of security.
Key terms
- network segmentation
- subnet
- VLAN
- screened subnet (DMZ)
- security zone
Why segment a network
In a flat network, every device can talk to every other device. If an adversary compromises one laptop, every server is one hop away.
Network segmentation divides the network into smaller, isolated segments, often called subnetworks or subnets. Traffic in one segment stays in that segment unless rules allow it to cross. That brings two big benefits:
- Containment. An attack on one segment can't easily spread to devices in other segments, so fewer devices are exposed.
- Different security levels. Each segment can have its own policies and controls. A segment with payroll data can be a higher security zone with strict rules, while a guest Wi-Fi segment can be a lower security zone.
Three ways to segment
- Subnetting splits a network by IP address. For example, staff devices might get addresses in 198.51.100.0/24 and the cameras in 192.0.2.0/24. The /24 means the first 24 bits (the first three numbers) are fixed, so each range covers the last number from 0 to 255. Traffic between subnets has to pass through a router or firewall, where it can be filtered.
- VLANs (virtual local area networks) are set up on switches. Devices plugged into the same physical switch can be put on different VLANs, and the switch keeps them logically separate as if they were on different switches. A school could put teachers, students and security cameras on three VLANs using the same hardware.
- A screened subnet, also called a demilitarized zone (DMZ), is a segment that sits between the internet and the internal network, created with firewall zones and rules. It holds the organization's public-facing servers, like its website. A typical design uses two firewalls: an outer one that lets the public reach the DMZ, and an inner one that tightly limits traffic from the DMZ into the private LAN. The DMZ is a lower security zone than the internal network, because outsiders are allowed in.
Port security on switches
Segmentation works alongside switch protections. Port security limits how many MAC addresses can use any single switch port. That stops MAC flooding, because the adversary's thousands of fake addresses get rejected instead of overflowing the switch's table. It also makes it harder to plug an unknown device into an open port.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Designing a segmented network
Elmwood Animal Hospital has a public website with online booking, an internal server with medical records, staff computers, a guest Wi-Fi for waiting-room visitors and some internet-connected security cameras. Propose a segmentation plan and justify it.
Show the solutionHide the solution
- Step 1: Put the public web server in a screened subnet (DMZ). The public must reach it, so keep it apart from everything private.
- Step 2: Put the medical records server in its own high-security segment that only staff computers can reach, through a firewall with strict rules.
- Step 3: Put staff computers in their own segment (a subnet or VLAN).
- Step 4: Put guest Wi-Fi in a low-security segment that can reach the internet but nothing internal.
- Step 5: Put the cameras in their own VLAN, since internet-connected devices are often weakly protected and shouldn't share a segment with records.
- Step 6: Justify with containment and zones: a compromise of the web server, a guest device or a camera stays in its segment, and the records segment gets the strictest controls.
Answer: DMZ for the web server; separate segments for the records server (highest security), staff computers, guest Wi-Fi (internet only) and cameras. A breach in any one segment is contained, and each segment gets controls that match its sensitivity.
- Example 2
Why the DMZ helps
An adversary takes over the web server in Elmwood's DMZ. Explain why the medical records are still protected, and name one way the protection could fail.
Show the solutionHide the solution
- Step 1: The web server sits in the DMZ, behind the outer firewall but outside the internal network.
- Step 2: The inner firewall strictly limits what DMZ servers can send into the internal network, so the adversary can't simply connect to the records server.
- Step 3: The protection fails if the inner firewall's rules are too loose, for example a rule allowing any traffic from the DMZ to the internal network.
Answer: The inner firewall blocks traffic from the DMZ into the internal network, so a hijacked web server can't reach the records server directly. Loose inner-firewall rules (like allowing all DMZ traffic inward) would break that protection.
Common mistakes
- Thinking a VLAN needs separate hardware. VLANs logically separate devices on the same physical switches.
- Putting public servers on the internal network. Public-facing servers belong in a screened subnet (DMZ).
- Calling the DMZ the most secure zone. It's lower security than the internal network, because outsiders are allowed to reach it.
- Saying segmentation stops all attacks. It contains them and lets each zone have its own controls; it doesn't prevent the first compromise.
On the exam
- Questions often ask why segmentation improves security. Name both reasons: it contains a breach to one segment, and it lets each segment have its own security level.
- Know which tool does what: subnets split by IP address, VLANs split on switches, and a screened subnet holds public-facing servers between the internet and the internal network.
Connected topics
Videos
Check yourself: 3.3 Protecting Networks: Segmentation
4 questions on 3.3 Protecting Networks: Segmentation. Pick an answer to see if you got it, and why.
A company's sales and finance computers all plug into the same physical switches. The network administrator wants to keep the two groups' traffic separate without buying new switches. Which technique fits best?
A network is divided into subnets. The accounting subnet covers the addresses 198.51.100.0 through 198.51.100.127, and the sales subnet covers 198.51.100.128 through 198.51.100.255. Which device is on the accounting subnet?
Which statement best describes network segmentation?
A network technician at a middle school notices that one switch port in an empty classroom is suddenly sending frames from more than 8,000 different MAC addresses. Shortly afterward, the switch begins sending every frame it receives out of every port.
Invented scenario
Which control would best prevent this attack?
0 of 4 answered