Micro-segmentation
Applying access policy to small groups of workloads, often a single workload or application, and enforcing it close to the workload rather than only at a network boundary.
Micro-segmentation narrows network segmentation down to workloads. Instead of drawing a few large zones with a firewall between them, it applies policy to small groups of systems, often one workload or one application, and enforces that policy near the workload itself: in a host-based or distributed firewall, or in the virtual switch that connects virtual machines. The aim is to control east-west traffic between systems inside the same environment, which a boundary control alone does not inspect, and so to limit lateral movement after a compromise. NIST SP 800-207 describes micro-segmentation as one way to deploy a zero trust architecture.
Two confusions are common. First, zero trust and micro-segmentation are not the same thing: zero trust is the design approach, and micro-segmentation is one mechanism for enforcing it. Second, the ISC2 exam outline pairs micro-segmentation with network overlays and encapsulation. An overlay, such as VXLAN, carries separate segments across a shared physical network, but the overlay is only the transport. Encapsulation separates traffic but gives no confidentiality by itself, and the protection comes from the policy applied, not from the tunnel.
Exam relevance: a scenario is likely to ask how to stop an attacker moving between servers in the same data centre segment. Candidates are expected to recognise micro-segmentation and to avoid treating an overlay as the control.