A security team is implementing a defense-in-depth strategy and wants to ensure that even if an attacker compromises a web server, the attacker cannot easily move laterally to the internal database server. Which security principle is being applied when the team segments the network and restricts traffic between the web tier and the database tier?
Network segmentation divides a network into isolated zones and enforces traffic controls between them. By restricting traffic from the web tier to the database tier, the team limits lateral movement, so a compromised web server cannot freely reach the database. This directly matches the described control and its purpose.
Why this answer
Segmenting the network and restricting traffic between the web and database tiers limits an attacker's ability to move laterally after compromising a web server. This is the principle of network segmentation, which reduces the attack surface and contains breaches within a zone.
Exam trap
The trap here is choosing the umbrella term defense in depth when the scenario describes the specific control of network segmentation.