Memory hook: Trace every trust boundary, including the physical one.
Must remember
Separate the data plane carrying traffic, control plane deciding forwarding and management plane administering devices. Protect management with dedicated access paths, strong identity, logging and recovery capability. Out-of-band management can remain reachable when the production network fails, but it needs independent protection.
Layering helps locate controls: physical media, Ethernet switching, IP routing, transport and application protocols solve different problems. VLANs separate broadcast domains; routing/firewall policy controls communication between them. VRFs separate routing tables; overlays encapsulate traffic but do not automatically encrypt it. IPsec can protect IP traffic, TLS application transport and SSH administration. Deprecated SSL should not be treated as a current secure protocol.
North–south traffic enters/leaves an environment; east–west traffic moves within it. Microsegmentation restricts lateral movement. SDN centralizes or programs control; securing its controllers and APIs is crucial. SASE combines networking and security delivery concepts; it does not remove endpoint or identity responsibilities.
Bandwidth is capacity, throughput delivered work, latency delay, jitter variation and loss missing packets. Voice/video suffer from jitter and loss even when aggregate bandwidth is high. Storage/converged networks such as iSCSI carry sensitive traffic too; shared infrastructure needs isolation and capacity planning. CDNs cache/distribute content but require correct origin protection and cache policy.
Distributed systems introduce partial failures, retry duplication, consistency tradeoffs and dependencies. Containers share kernel risk; serverless reduces server administration while preserving code/data/identity risks; edge and IoT add physical exposure and constrained updates. Industrial systems require safety-aware controls.
Facility choices address natural and human hazards, access zoning, secure cabling, evidence/media storage, power, cooling, humidity and appropriate fire protection. Human life and safe egress come first. Redundant power paths sharing one upstream failure point are not truly independent. Test emergency communication and personnel procedures as well as machines.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Voice calls break despite spare bandwidth | Inspect latency, jitter, loss and queueing. |
| Control-plane compromise risk | Restrict and monitor controller/API administration. |
| Disaster affects a shared building | Independent geography, utilities and tested continuity processes. |
Traps
- Two components sharing one power source do not eliminate that source’s failure.
- Encapsulation alone is not confidentiality.
Active recall
1. East–west traffic means what?
Traffic between systems inside an environment.
2. Why secure the management plane separately?
Administrative compromise can alter or bypass data-plane controls.
3. Latency versus jitter?
Latency is delay; jitter is variation in delay.
4. Does a VLAN automatically block routed access?
No. Inter-VLAN routing and policy determine communication.
5. What outranks equipment preservation in a facility emergency?
Human safety and lawful emergency procedures.