Courseiva
hardMultiple Choice

200-201 Practice Question: A security analyst for a medium-sized enterprise

You are a security analyst for a medium-sized enterprise. The network includes a DMZ with a web server (10.0.1.10) and a database server (10.0.2.10) in the internal network. Users access the web server via HTTPS from the internet. The web server queries the database server on TCP 3306. Recently, users reported that the web application sometimes returns database errors. You review firewall logs and see the following:

- Allowed inbound HTTPS to 10.0.1.10 from various external IPs. - Denied outbound from 10.0.1.10 to 10.0.2.10 on port 3306. - Allowed outbound from 10.0.1.10 to external IPs on port 443.

You also notice that the web server's outbound traffic to the database server is being blocked. The firewall has a default deny rule. Which action should you take to restore normal operation while maintaining security?

⚠ Common exam trap

Cisco often tests the misconception that you need an inbound rule for the database server when the traffic is actually initiated from the web server outbound, leading candidates to choose Option A or C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a rule allowing outbound traffic from the web server IP (10.0.1.10) to the database server IP (10.0.2.10) on TCP 3306.

The firewall logs show that outbound traffic from the web server (10.0.1.10) to the database server (10.0.2.10) on TCP 3306 is being denied, which causes the database errors. Since the web server initiates the connection to the database, a rule allowing this specific outbound traffic from the web server to the database server on port 3306 restores functionality while maintaining the default-deny posture. This is the most secure approach because it permits only the necessary traffic between the two specific hosts and port, without opening broader access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a rule allowing inbound traffic on TCP 3306 to the database server from any source.

    Why it's wrong here

    The denial is outbound from the web server, so an inbound rule on TCP 3306 never matches that traffic. Inbound database rules are for external clients connecting to a database, not for a DMZ host initiating queries to an internal server.

  • ✗

    Move the database server to the DMZ to avoid firewall restrictions.

    Why it's wrong here

    Relocating the database into the DMZ exposes it directly to internet-facing threats and breaks the tiered design; the block is an outbound DMZ-to-internal rule, not a placement issue. DMZ placement suits servers that must accept untrusted inbound connections directly.

  • ✗

    Create a rule allowing all outbound traffic from the DMZ to the internal network.

    Why it's wrong here

    Allowing all outbound DMZ-to-internal traffic restores database connectivity but grants the web server unrestricted reach into the internal network, violating DMZ segmentation. The denied log shows only TCP 3306 to 10.0.2.10 is required. Broad DMZ-to-internal rules suit trusted management subnets, not internet-facing hosts.

  • ✓

    Create a rule allowing outbound traffic from the web server IP (10.0.1.10) to the database server IP (10.0.2.10) on TCP 3306.

    Why this is correct

    The default deny rule is dropping the web server's database queries, causing the application errors. A rule permitting only 10.0.1.10 to reach 10.0.2.10 on TCP 3306 restores that specific flow while keeping all other outbound traffic blocked, preserving the DMZ segmentation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.