Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain the role of physical security controls like cameras and locks
- Describe honeypots and honeynets as deception technologies
- Explain why IoT/IIoT and SCADA/ICS/OT environments require dedicated network segmentation
- Describe segmentation considerations for guest networks and BYOD devices
- Explain data locality and the purpose of compliance frameworks like PCI DSS and GDPR
Key Terms
| Term | Definition |
|---|---|
| Honeypot | A single decoy system designed to attract and detect attackers, with no legitimate business traffic ever expected to touch it |
| Honeynet | A larger decoy network of multiple honeypots, used to study broader attacker behavior |
| SCADA/ICS/OT | Operational technology systems controlling physical industrial processes, historically designed without network security in mind |
| BYOD (Bring Your Own Device) | Personally owned devices connecting to corporate resources, requiring a distinct security policy from corporate-owned devices |
| Data Locality | A legal or regulatory requirement that data physically reside within specific geographic or jurisdictional boundaries |
Explanation
Closing Out Objective 4.1
The previous lesson covered logical access controls — proving identity and controlling what that identity can do. This final lesson in objective 4.1 rounds out basic security concepts with the physical, deceptive, and structural sides of security: controlling physical access, detecting attackers actively, isolating high-risk device categories, and meeting regulatory obligations around where data actually lives.Physical Security: Cameras and Locks
Physical security remains a genuinely necessary layer even in a heavily virtualized, cloud-connected world — an attacker with physical access to a device or facility can often bypass logical controls entirely. Two of the most fundamental physical controls are:
- Cameras, which serve both as a deterrent (a visible camera discourages attempted physical intrusion in the first place) and as an investigative tool after the fact, providing evidence of who accessed a space and when.
- Locks, which directly restrict physical access to spaces and equipment — the same principle behind the lockable rack cabinets mentioned in earlier physical installation coverage, applied more broadly to server rooms, wiring closets, and entire facilities.
Physical security and logical security work together rather than substituting for each other: a perfectly configured firewall does little good if an attacker can simply walk up to an unsecured switch and plug in directly.
Deception Technology: Honeypots and Honeynets
Deception technology takes a fundamentally different approach from most security controls — rather than only trying to block attackers, it deliberately creates convincing decoy targets designed to attract them.
- A honeypot is a single decoy system, deliberately made to look like a legitimate, valuable target, with no actual business function and no legitimate traffic ever expected to reach it. Since any traffic touching a honeypot is inherently suspicious — a real user would have no reason to interact with it — honeypots serve as an early warning system, often detecting an attacker’s presence well before they reach anything genuinely valuable.
- A honeynet extends this concept into an entire decoy network of multiple honeypots, creating a more elaborate, realistic-looking environment. This lets security teams observe more sophisticated attacker behavior across multiple systems, rather than a single isolated interaction.

The value of deception technology comes specifically from that “no legitimate reason to be here” property — it’s one of the few security tools where any activity at all is inherently a signal worth investigating.
Network Segmentation Enforcement: IoT/IIoT and SCADA/ICS/OT
Certain categories of devices carry security risk significant enough that isolating them onto their own dedicated network segments — commonly using VLANs as the mechanism — is considered essential rather than optional:- IoT (Internet of Things) devices — smart cameras, sensors, connected appliances — are frequently built with weak security by design, minimal patching support, and limited configurability, making them attractive, relatively easy targets if left on the same network segment as sensitive business systems.
- IIoT (Industrial Internet of Things) extends this same device category into manufacturing and industrial settings specifically.
- SCADA, ICS, and OT (Operational Technology) systems control physical industrial processes — manufacturing equipment, utility infrastructure, building systems. These were historically designed assuming they’d never be exposed to a broader network at all, and consequently often lack the security hardening expected of modern IT systems entirely. Segmenting OT away from the general IT network isn’t a best practice suggestion here — it’s frequently treated as an absolute requirement, since a compromise reaching into OT systems can have real-world physical consequences well beyond a typical data breach.

Guest and BYOD Network Segmentation
Two more device categories call for their own deliberate segmentation approach:
A guest network isolates untrusted, unmanaged visitor devices from the internal corporate network entirely — a pattern already covered in this course’s discussion of SSID types and guest network configuration. A guest device should have internet access without any path back into internal systems.BYOD (Bring Your Own Device) covers personally owned devices — employee phones, laptops — that need some level of access to corporate resources but aren’t fully managed or controlled by the organization the way a corporate-issued device is. BYOD policy and segmentation typically sit somewhere between full corporate device trust and complete guest-network isolation, often combined with additional controls limiting exactly what a BYOD device can reach.
Data Locality and Regulatory Compliance
Beyond technical segmentation, organizations often face legal obligations about where data physically resides and how it’s protected:
- Data locality requires that certain data physically remain within specific geographic or jurisdictional boundaries — a country’s regulations might require that citizens’ personal data never leave that country’s borders, regardless of where the organization processing it is headquartered.
- PCI DSS (Payment Card Industry Data Security Standard) sets specific security requirements for any organization handling payment card data, covering everything from network segmentation of cardholder data environments to encryption and access control requirements.
- GDPR (General Data Protection Regulation) is the EU’s data protection regulation, governing how personal data belonging to EU residents must be collected, processed, and protected — with real regulatory consequences for organizations that fail to comply, regardless of where that organization itself is based.

Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- Any traffic reaching a system with no legitimate business function is a strong signal of a honeypot detecting unauthorized activity.
- A network segment isolating manufacturing control systems from the general corporate network describes OT/ICS/SCADA segmentation, treated as essential rather than optional.
- A visitor’s personal device connecting to internet-only access with no path to internal resources describes a guest network; an employee’s personal phone with limited access to specific corporate resources describes BYOD.
- A requirement that customer data physically stay within a specific country’s borders describes data locality, distinct from general encryption or access control requirements.
Common Exam Traps
- A honeypot’s value depends entirely on it having no legitimate traffic. If real business systems ever interact with it, the “any activity is suspicious” property that makes it useful is compromised.
- IoT/IIoT and OT/SCADA/ICS segmentation isn’t just a best practice recommendation — it’s frequently treated as mandatory, given the potential physical-world consequences of a compromise reaching operational technology.
- Guest networks and BYOD are not the same segmentation model. Guest assumes zero trust and internet-only access; BYOD typically allows some level of controlled access to specific corporate resources.
- PCI DSS and GDPR serve different regulatory purposes. PCI DSS specifically governs payment card data; GDPR governs personal data belonging to EU residents more broadly — don’t conflate the two as interchangeable compliance frameworks.
- Data locality is a jurisdictional/geographic requirement, distinct from encryption or general security controls. A perfectly encrypted dataset can still violate data locality requirements if it’s stored in the wrong country.
Lesson 4.1.4 Practice Quiz — Physical Security, Deception Technology & Segmentation Enforcement
17 questions covering cameras/locks, honeypots/honeynets, IoT/OT segmentation, guest/BYOD networks, and compliance frameworks.
N10-009 · Domain 4.1Summary
Physical security controls like cameras and locks remain essential even in modern networks, since physical access can bypass logical controls entirely.
Honeypots are single decoy systems and honeynets are larger decoy networks, both valuable specifically because any interaction with them is inherently suspicious.
IoT, IIoT, and SCADA/ICS/OT devices require dedicated network segmentation — often mandatory rather than optional — given their typically weak built-in security and, for OT specifically, the real-world physical consequences of compromise.
Guest networks isolate untrusted visitor devices with internet-only access; BYOD requires its own distinct policy allowing controlled, limited access to specific corporate resources.
Data locality, PCI DSS, and GDPR each impose distinct regulatory requirements around where data resides and how specific categories of data must be protected.
This lesson completes objective 4.1 (Basic Network Security Concepts) at 4/4 lessons; the next lessons move into objective 4.2, types of attacks.



