Memory hook: Reduce exposure; separate trust; inspect the right layer.
Must remember
Security responsibility changes across IaaS, PaaS and SaaS. Customers retain responsibilities for their data, identities and configuration even when infrastructure is managed. Virtual machines share a hypervisor; containers normally share the host kernel. Isolation, patching and image provenance remain important.
Segment systems by sensitivity and function: user networks, guests, servers, management, IoT and operational technology. A screened subnet/DMZ hosts externally reachable services while restricting movement inward. Air gaps and logical isolation differ; removable media and maintenance paths can still introduce risk. Industrial systems prioritize safety and availability, so patching may require controlled maintenance and compensating safeguards.
| Control | Deciding role |
|---|---|
| Stateful firewall / ACL | Permit or deny network flows at the relevant enforcement point. |
| WAF | Inspect web application requests; supplement secure application code. |
| IDS / IPS | Detect / potentially block suspicious traffic. |
| Proxy / secure web gateway | Mediate outbound web access and policy. |
| NAC | Assess/authorize device network admission. |
| VPN | Protect a tunnel; endpoint compromise remains possible. |
| DLP | Discover and restrict sensitive-data movement. |
| EDR / XDR | Endpoint detection/response / correlation across broader sources. |
Choose fail-open versus fail-closed behavior according to safety and availability requirements. A load balancer improves distribution/availability; it is not a substitute for authentication. Secure management interfaces separately from application traffic, prefer encrypted protocols and restrict administrative access.
Wireless protection includes WPA3 or appropriate enterprise authentication, secure onboarding, guest isolation and removal of legacy protocols. An evil twin imitates a legitimate network; validate the authentication server certificate in enterprise Wi-Fi rather than accepting any certificate prompt.
IaC makes configuration repeatable but also makes a bad template repeatable. Review plans, scan configurations, protect state and control deployment credentials.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Block common web-request attacks | WAF plus application-layer fixes. |
| Untrusted guest devices | Separate network and restricted routing/access. |
| Legacy industrial controller cannot be patched now | Approved segmentation, monitoring and maintenance planning. |
Traps
- A VPN does not make the endpoint trustworthy.
- Containers are not equivalent to separate hardware trust boundaries.
Active recall
1. IDS versus IPS?
IDS detects/alerts; an IPS can enforce blocking in the traffic path.
2. Why isolate management interfaces?
Compromise of administration can bypass normal application protections.
3. Why not immediately patch every industrial system?
Safety, compatibility and availability require controlled testing and maintenance.
4. What can a WAF not replace?
Correct authentication, authorization and secure application design.
5. What is shared responsibility in SaaS?
The provider runs more of the stack, but customers still manage appropriate identities, data and tenant configuration.