Entity Zones are designed to distinguish entities that might otherwise appear identical because they use overlapping or duplicated identifiers, such as the same RFC1918 address ranges in separate business environments. This makes them the appropriate feature when an acquired company uses IP address space that overlaps with the parent organization.
Without zoning, an address such as 10.1.20.15 could ambiguously refer to systems in two different networks. By associating those assets with separate entity zones , Enterprise Security can preserve distinct lookup and enrichment contexts so that the same IP value can resolve to the correct asset according to its organizational or network boundary.
This is especially important to the Assets and Identities Framework , because asset enrichment affects priority, ownership, risk attribution, and investigation context. Incorrectly merging two assets that share an IP address could cause risk to be assigned to the wrong system or produce misleading identity and asset information.
Entity Definitions describe how entities are identified, while Asset Classes and annotations provide classification or descriptive context; they do not specifically solve overlapping address-space ambiguity.
The supplied PDF covers Assets & Identities, entity enrichment, and risk prioritization, but not this exact Entity Zones stem.
Study Guide topics: Assets & Identities Framework, Entity Zones, overlapping IP space, asset enrichment, entity resolution, risk context.