HOTSPOT In the network design below, where is the MOST secure Local Area Network (LAN) segment to deploy a Wireless Access Point (WAP) that provides contractors access to the Internet and authorized enterprise services?
LAN 4 (the DMZ) is the best spot for this WAP if contractors only need Internet and limited enterprise access. DMZ design keeps traffic from hitting internal resources directly, which lines up with least privilege. Pretty standard CISSP logic but open for debate if business needs were different!
I'd pick LAN 3 since it's separated from the internal LAN but still on the inside perimeter, so it feels more secure than putting external users right into a DMZ. Not fully sure though, maybe there's something I'm missing about DMZ vs internal segmentation. Open to corrections if I'm off here.
