Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate network. Which primary objective does this control serve?

Network segmentation limits lateral movement, so a breach in one zone is contained and cannot easily reach critical systems such as payments. It is a protective containment control, not a backup recovery, fraud monitoring or patching mechanism.

  1. ALimiting lateral movement so a compromise in one zone does not spread to critical systemsCorrect
  2. BSpeeding up recovery of data from backups
  3. CDetecting insider fraud through transaction monitoring
  4. DEnsuring software patches are applied faster

Explanation

Segmentation restricts traffic between zones, containing an intrusion and hindering lateral movement toward critical assets. It is a protective, containment control rather than a recovery, fraud-monitoring or patching measure.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions