An enterprise network implements perimeter firewalls, host-based firewalls, internal VLAN segmentation, and endpoint detection agents. Despite this multi-layered defense, an attacker successfully exfiltrates data through an unmonitored external cloud storage provider via standard HTTPS. Which security control principle was primarily neglected in this defense-in-depth architecture?
Trap 1: Deploying a third perimeter firewall to add redundancy to the…
Adding another perimeter firewall simply duplicates the existing ingress and egress inspection logic without addressing visibility into outbound cloud traffic protocols. Redundancy improves availability but fails to solve blind spots in egress data monitoring.
Trap 2: Implementing strict egress filtering and content inspection for all…
Strict egress filtering involves blocking unauthorized ports, but since HTTPS operates over port 443 which is typically required for business operations, simple port blocking is insufficient without deep packet inspection and cloud application visibility.
Trap 3: Upgrading host-based intrusion detection agents to isolate the…
Host isolation mitigates lateral movement and host compromise after an incident starts, but it does not address the fundamental architectural failure of failing to monitor and inspect outbound data channels leaving the internal enterprise boundary.
- A
Deploying a third perimeter firewall to add redundancy to the external gateway boundary
Why it fails: Adding another perimeter firewall simply duplicates the existing ingress and egress inspection logic without addressing visibility into outbound cloud traffic protocols. Redundancy improves availability but fails to solve blind spots in egress data monitoring.
- B
Implementing strict egress filtering and content inspection for all outbound TLS traffic
Why it fails: Strict egress filtering involves blocking unauthorized ports, but since HTTPS operates over port 443 which is typically required for business operations, simple port blocking is insufficient without deep packet inspection and cloud application visibility.
- C
Enforcing Cloud Access Security Broker capabilities with comprehensive egress traffic visibility and data loss prevention policies
Cloud Access Security Brokers provide critical visibility and enforcement points for SaaS and cloud storage traffic. Monitoring and restricting unauthorized data movement to external cloud platforms closes the critical data exfiltration gap left by standard firewalls.
- D
Upgrading host-based intrusion detection agents to isolate the compromised workstation automatically
Why it fails: Host isolation mitigates lateral movement and host compromise after an incident starts, but it does not address the fundamental architectural failure of failing to monitor and inspect outbound data channels leaving the internal enterprise boundary.