
AWS Certified Advanced Networking – Specialty (ANS-C01) Certification Guide
By :

Network segmentation is a security practice that involves dividing a network into smaller, isolated segments or zones. This is important because it helps contain potential threats. If a cyberattack occurs in one segment, it is far less likely to be able to spread to other segments, limiting the potential damage inflicted. By controlling and restricting access between these segments, organizations can better protect sensitive data and critical systems. Network segmentation also makes it easier to monitor and manage security by helping to identify and respond to suspicious activity more effectively. Overall, it strengthens an organization’s defense against cyberattacks.
In this section, you will learn how network segmentation is accomplished in AWS using virtual private clouds (VPCs), subnets, and firewalls. You’ll also see a comparison of distributed and centralized models for firewall deployment.
Zone-based security (sometimes...