Network Security 14% Lesson 4 of 8

Lesson 4.1.4 — Physical Security, Deception Technology & Segmentation Enforcement

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·6 min read
50% through domain
Illustration Of A Walled Garden With Fenced Plots Each Containing A Camera, Trap, Gear, And Globe Icon

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain the role of physical security controls like cameras and locks
  • Describe honeypots and honeynets as deception technologies
  • Explain why IoT/IIoT and SCADA/ICS/OT environments require dedicated network segmentation
  • Describe segmentation considerations for guest networks and BYOD devices
  • Explain data locality and the purpose of compliance frameworks like PCI DSS and GDPR

Key Terms

TermDefinition
HoneypotA single decoy system designed to attract and detect attackers, with no legitimate business traffic ever expected to touch it
HoneynetA larger decoy network of multiple honeypots, used to study broader attacker behavior
SCADA/ICS/OTOperational technology systems controlling physical industrial processes, historically designed without network security in mind
BYOD (Bring Your Own Device)Personally owned devices connecting to corporate resources, requiring a distinct security policy from corporate-owned devices
Data LocalityA legal or regulatory requirement that data physically reside within specific geographic or jurisdictional boundaries

Explanation

Closing Out Objective 4.1

The previous lesson covered logical access controls — proving identity and controlling what that identity can do. This final lesson in objective 4.1 rounds out basic security concepts with the physical, deceptive, and structural sides of security: controlling physical access, detecting attackers actively, isolating high-risk device categories, and meeting regulatory obligations around where data actually lives.

Physical Security: Cameras and Locks

Physical security remains a genuinely necessary layer even in a heavily virtualized, cloud-connected world — an attacker with physical access to a device or facility can often bypass logical controls entirely. Two of the most fundamental physical controls are:

  • Cameras, which serve both as a deterrent (a visible camera discourages attempted physical intrusion in the first place) and as an investigative tool after the fact, providing evidence of who accessed a space and when.
  • Locks, which directly restrict physical access to spaces and equipment — the same principle behind the lockable rack cabinets mentioned in earlier physical installation coverage, applied more broadly to server rooms, wiring closets, and entire facilities.

Physical security and logical security work together rather than substituting for each other: a perfectly configured firewall does little good if an attacker can simply walk up to an unsecured switch and plug in directly.

Deception Technology: Honeypots and Honeynets

Deception technology takes a fundamentally different approach from most security controls — rather than only trying to block attackers, it deliberately creates convincing decoy targets designed to attract them.

  • A honeypot is a single decoy system, deliberately made to look like a legitimate, valuable target, with no actual business function and no legitimate traffic ever expected to reach it. Since any traffic touching a honeypot is inherently suspicious — a real user would have no reason to interact with it — honeypots serve as an early warning system, often detecting an attacker’s presence well before they reach anything genuinely valuable.
  • A honeynet extends this concept into an entire decoy network of multiple honeypots, creating a more elaborate, realistic-looking environment. This lets security teams observe more sophisticated attacker behavior across multiple systems, rather than a single isolated interaction.
Diagram Comparing A Single Decoy Honeypot System Against A Larger Honeynet Of Multiple Connected Decoy Systems
How A Single Honeypot Compares To A Larger Honeynet Of Decoy Systems

The value of deception technology comes specifically from that “no legitimate reason to be here” property — it’s one of the few security tools where any activity at all is inherently a signal worth investigating.

Network Segmentation Enforcement: IoT/IIoT and SCADA/ICS/OT

Certain categories of devices carry security risk significant enough that isolating them onto their own dedicated network segments — commonly using VLANs as the mechanism — is considered essential rather than optional:
  • IoT (Internet of Things) devices — smart cameras, sensors, connected appliances — are frequently built with weak security by design, minimal patching support, and limited configurability, making them attractive, relatively easy targets if left on the same network segment as sensitive business systems.
  • IIoT (Industrial Internet of Things) extends this same device category into manufacturing and industrial settings specifically.
  • SCADA, ICS, and OT (Operational Technology) systems control physical industrial processes — manufacturing equipment, utility infrastructure, building systems. These were historically designed assuming they’d never be exposed to a broader network at all, and consequently often lack the security hardening expected of modern IT systems entirely. Segmenting OT away from the general IT network isn’t a best practice suggestion here — it’s frequently treated as an absolute requirement, since a compromise reaching into OT systems can have real-world physical consequences well beyond a typical data breach.
Diagram Showing Iot, Iiot, And Ot/Scada/Ics Devices Each Isolated Behind Firewalls Into Their Own Segments Away From The Corporate It Network
Why Iot, Iiot, And Ot Devices Are Isolated Onto Dedicated Network Segments

Guest and BYOD Network Segmentation

Two more device categories call for their own deliberate segmentation approach:

A guest network isolates untrusted, unmanaged visitor devices from the internal corporate network entirely — a pattern already covered in this course’s discussion of SSID types and guest network configuration. A guest device should have internet access without any path back into internal systems.

BYOD (Bring Your Own Device) covers personally owned devices — employee phones, laptops — that need some level of access to corporate resources but aren’t fully managed or controlled by the organization the way a corporate-issued device is. BYOD policy and segmentation typically sit somewhere between full corporate device trust and complete guest-network isolation, often combined with additional controls limiting exactly what a BYOD device can reach.

Data Locality and Regulatory Compliance

Beyond technical segmentation, organizations often face legal obligations about where data physically resides and how it’s protected:

  • Data locality requires that certain data physically remain within specific geographic or jurisdictional boundaries — a country’s regulations might require that citizens’ personal data never leave that country’s borders, regardless of where the organization processing it is headquartered.
  • PCI DSS (Payment Card Industry Data Security Standard) sets specific security requirements for any organization handling payment card data, covering everything from network segmentation of cardholder data environments to encryption and access control requirements.
  • GDPR (General Data Protection Regulation) is the EU’s data protection regulation, governing how personal data belonging to EU residents must be collected, processed, and protected — with real regulatory consequences for organizations that fail to comply, regardless of where that organization itself is based.
Diagram Showing A Data Server Icon Confined Within A Highlighted Geographic Region Alongside Pci Dss And Gdpr Compliance Badges
How Data Locality, Pci Dss, And Gdpr Each Impose Distinct Regulatory Requirements

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • Any traffic reaching a system with no legitimate business function is a strong signal of a honeypot detecting unauthorized activity.
  • A network segment isolating manufacturing control systems from the general corporate network describes OT/ICS/SCADA segmentation, treated as essential rather than optional.
  • A visitor’s personal device connecting to internet-only access with no path to internal resources describes a guest network; an employee’s personal phone with limited access to specific corporate resources describes BYOD.
  • A requirement that customer data physically stay within a specific country’s borders describes data locality, distinct from general encryption or access control requirements.

Common Exam Traps

  • A honeypot’s value depends entirely on it having no legitimate traffic. If real business systems ever interact with it, the “any activity is suspicious” property that makes it useful is compromised.
  • IoT/IIoT and OT/SCADA/ICS segmentation isn’t just a best practice recommendation — it’s frequently treated as mandatory, given the potential physical-world consequences of a compromise reaching operational technology.
  • Guest networks and BYOD are not the same segmentation model. Guest assumes zero trust and internet-only access; BYOD typically allows some level of controlled access to specific corporate resources.
  • PCI DSS and GDPR serve different regulatory purposes. PCI DSS specifically governs payment card data; GDPR governs personal data belonging to EU residents more broadly — don’t conflate the two as interchangeable compliance frameworks.
  • Data locality is a jurisdictional/geographic requirement, distinct from encryption or general security controls. A perfectly encrypted dataset can still violate data locality requirements if it’s stored in the wrong country.

Lesson 4.1.4 Practice Quiz — Physical Security, Deception Technology & Segmentation Enforcement

17 questions covering cameras/locks, honeypots/honeynets, IoT/OT segmentation, guest/BYOD networks, and compliance frameworks.

N10-009 · Domain 4.1
Question 1Plain
What is a honeypot?
A honeypot is a single decoy system with no legitimate business function, designed to attract and detect attackers.
Question 2Plain
Why is segmenting OT/SCADA/ICS systems from the general IT network so critical?
OT/SCADA/ICS systems control physical industrial processes, so a compromise can cause real-world physical harm — a much higher stake than a typical IT data breach.
Question 3Plain
What does GDPR govern?
GDPR is the EU's data protection regulation, governing how personal data of EU residents must be handled — distinct from PCI DSS, which specifically covers payment card data.
Question 4Choose Two
Which two statements about honeypots are correct? (Choose two.)
Honeypots are single decoys with no legitimate traffic expected — that absence of legitimate use is exactly what makes any interaction with them suspicious.
Question 5Choose Two
Which two statements about IoT devices are correct? (Choose two.)
IoT devices' typically weak built-in security is exactly why dedicated segmentation is recommended — they are not inherently more secure and do benefit from isolation.
Question 6Choose Two
Which two statements correctly distinguish guest networks from BYOD? (Choose two.)
Guest networks isolate visitors to internet-only access; BYOD sits between full corporate trust and guest isolation, allowing controlled access to specific resources — the two models are distinct, and BYOD devices are not fully corporate-managed.
Question 7Scenario
A security team wants to detect an attacker's presence early, well before they reach any genuinely valuable system. What tool fits this goal?
A honeypot's core value is exactly this — detecting attacker presence early, since any interaction with it is inherently suspicious.
Question 8Scenario
A manufacturing plant wants to isolate its industrial control systems (PLCs, SCADA) from the general corporate IT network. What is this an example of?
Isolating industrial control systems from general IT is exactly the OT/ICS/SCADA segmentation this lesson covers, treated as essential given the physical-world stakes.
Question 9Scenario
A visitor at an office wants Wi-Fi access, but should only be able to reach the internet with no path into internal company systems. What should be configured?
Internet-only access for an untrusted visitor device is exactly the guest network model.
Question 10Scenario
An employee wants to use their personal phone to check corporate email and access a couple of specific work apps, without the device being fully corporate-managed. What policy category applies?
A personally owned device needing limited, controlled access to specific corporate resources is exactly the BYOD scenario.
Question 11Scenario
A company must ensure that data belonging to its EU customers never leaves data centers physically located within the EU. What requirement is this?
A requirement that data physically remain within a specific geographic/jurisdictional boundary is exactly data locality — often tied to regulations like GDPR.
Question 12Exhibit
Based on this network log, what is most likely being detected?
Network Log: Connection attempt to: 10.50.99.5 (decoy-finance-db, no real business function) Legitimate traffic to this host: NEVER expected Result: FLAGGED — investigate source immediately
A decoy host explicitly noted as having no real business function, with any connection immediately flagged, is a honeypot doing exactly its job.
Question 13Exhibit
Based on this network diagram description, what is being enforced?
Network Segments: Corporate IT VLAN: 192.168.10.0/24 OT/SCADA VLAN: 192.168.99.0/24 (isolated, firewall-restricted, no direct IT access)
A separate, firewall-restricted VLAN specifically for OT/SCADA, isolated from the corporate IT VLAN, is exactly OT network segmentation.
Question 14Exhibit
Based on this configuration, what type of network is this?
SSID: Company-Guest Access: Internet only Internal network access: BLOCKED Authentication: Captive portal, no corporate credentials required
Internet-only access, blocked internal access, and a captive portal with no corporate credentials are all classic guest network characteristics.
Question 15Exhibit
Based on this policy document, what category of device access does this describe?
Policy: Personal Device Access Requirement: MDM enrollment required Access Granted: Corporate email, calendar app only Access Denied: Internal file shares, admin systems Device Ownership: Employee-owned
Employee-owned devices with limited, specific corporate app access — more than guest, less than full corporate trust — is exactly BYOD.
Question 16Exhibit
Based on this compliance requirement, which framework is being referenced?
Compliance Requirement: Standard: PCI DSS Requirement: Cardholder data environment must be logically segmented from the rest of the network Scope: Any system storing, processing, or transmitting payment card data
The requirement explicitly names PCI DSS and addresses payment card data specifically, distinct from GDPR's broader personal data scope.
Question 17Exhibit
Based on this requirement, what concept is being enforced?
Data Residency Requirement: Regulation: GDPR-aligned data residency clause Requirement: EU customer personal data must be stored exclusively in EU-based data centers Cross-border transfer: Prohibited without additional safeguards
A requirement that data physically remain within a specific geographic boundary, tied to GDPR, is exactly data locality.
📝

Summary

Physical security controls like cameras and locks remain essential even in modern networks, since physical access can bypass logical controls entirely.

Honeypots are single decoy systems and honeynets are larger decoy networks, both valuable specifically because any interaction with them is inherently suspicious.

IoT, IIoT, and SCADA/ICS/OT devices require dedicated network segmentation — often mandatory rather than optional — given their typically weak built-in security and, for OT specifically, the real-world physical consequences of compromise.

Guest networks isolate untrusted visitor devices with internet-only access; BYOD requires its own distinct policy allowing controlled, limited access to specific corporate resources.

Data locality, PCI DSS, and GDPR each impose distinct regulatory requirements around where data resides and how specific categories of data must be protected.

This lesson completes objective 4.1 (Basic Network Security Concepts) at 4/4 lessons; the next lessons move into objective 4.2, types of attacks.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.