A facility insists its single perimeter firewall between IT and OT is 'enough' segmentation. Which limitation most undermines that assumption?
- A.Perimeter firewalls cannot pass industrial protocols
- B.Perimeter firewalls automatically expire after one year
- C.A single perimeter provides no internal containment, so once an attacker is inside the OT zone they move freely east-west
- D.Perimeter firewalls block all legitimate vendor access permanently
Why C is correct
A lone perimeter firewall implements only a hard shell with a soft interior: nothing constrains lateral movement once inside. Internal zoning and microsegmentation are needed so a breach of one area does not expose the entire OT environment.
Know someone studying for OT Security Fundamentals? Send them this one.