A facility insists its single perimeter firewall between IT and OT is 'enough' segmentation. Which limitation most undermines that assumption?
- A.Perimeter firewalls cannot pass industrial protocols, a guarantee written into the base specification of every fieldbus protocol
- B.Perimeter firewalls block all legitimate vendor access permanently leaving support tunnels as the only sanctioned remote path
- C.Perimeter firewalls automatically expire after one year
- D.A single perimeter provides no internal containment, so once an attacker is inside the OT zone they move freely east-west
Why D is correct
A lone perimeter firewall implements only a hard shell with a soft interior: nothing constrains lateral movement once inside. Internal zoning and microsegmentation are needed so a breach of one area does not expose the entire OT environment.
Know someone studying for OT Security Fundamentals? Send them this one.