TechKnowSurge
ISC2 CC 4.2 NIST 800-53 SC-32 CompTIA Security+ 3.2 CompTIA Network+ 4.3 ISC2 CC 4.1 NIST 800-53 SC-7 CompTIA Network+ 4.1
InteractiveSecurityFree

Which Segment Does It Belong In?

Web server, payroll database, switch consoles, smart thermostat: which segment does each belong in?

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Segmentation divides the network so that resources are separated by role, department or kind of device. Someone in administration does not automatically reach operations' servers, and a compromised machine in one segment cannot simply reach the others. The lesson's segments: - The screened subnet, also called the DMZ (demilitarized zone): a separate network for the servers the public must reach, such as the web servers. Firewall rules let outside users in to those servers. If the servers sat on the internal network and were compromised, the attacker would be inside; in the screened subnet, the internal network is still protected. - Segments by department or role: administration, operations and sales each with their own servers, data and access. - A management network: the switches, servers and database servers all need managing, and SNMP monitoring traffic runs there too. Only the people who manage the equipment can reach it, so others cannot see or reach the back ends. - IoT, OT and embedded systems: smart thermostats and appliances (Internet of Things), robots and assembly lines (operational technology), and devices with a computer built in (embedded systems). They are often not updated and hard to see into, so they get their own segment, even on many home networks. How it is built: before VLANs, every segment needed its own switch. A VLAN (virtual LAN) splits one switch into several separate LANs, port by port. Traffic between VLANs has to pass through a router or firewall, which is where it can be controlled. Micro-segmentation takes the idea further, into very small segments, so traffic can be controlled closely.

What you'll learn

Aligned to

ISC2 CC
4.2 Understand network security architecture
4.1 Understand network security
NIST 800-53
SC-32 System Partitioning
SC-7 Boundary Protection
CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions.
4.1 Explain the importance of basic network security concepts.

Key terms

Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Screened Subnet
A dedicated network segment that hosts publicly accessible services, isolating them from the internal network so that a compromised host cannot directly access internal resources.
Demilitarized Zone
DMZ
A network segment that sits between a trusted internal network and an untrusted external network, hosting public-facing services.
Management VLAN
A VLAN reserved for administrative access to network devices, separating switch and router management traffic from user data traffic so that a compromised end device does not share a broadcast domain with the management addresses.
Internet of Things
IoT
A network of physical devices embedded with sensors and software that connect and exchange data over the internet.
Operational Technology
OT
Operational Technology refers to hardware and software systems that monitor and control physical devices, processes, and infrastructure in industrial and critical environments, requiring specialized security approaches distinct from traditional IT.
Embedded System
A computer system built and optimized for a specific device or function, typically smaller than a general-purpose computer.
Virtual LAN
VLAN
A logical grouping of network devices that behave as if they are on the same network regardless of physical location.
Micro-segmentation
A security technique that breaks a network into very small, granular segments to provide fine-grained traffic control and limit lateral movement between workloads.
Lateral Movement
A MITRE ATT&CK tactic in which an adversary pivots from one compromised system to other systems within the same network environment.

Topics

Network Segmentation Screened Subnet Internet Of Things Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →