easyMultiple Choice
CAS-004 Practice Question: A network architect is designing a DMZ for a web…
A network architect is designing a DMZ for a web application. Which of the following is the MOST appropriate placement for a reverse proxy?
⚠ Common exam trap
Many candidates mistakenly think a reverse proxy belongs inside the internal network for better performance or easier management, but the correct placement is in the DMZ to enforce security boundaries and protect internal resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the DMZ
A reverse proxy is placed in the DMZ to act as an intermediary for client requests to the web application. It terminates external connections, inspects traffic, and forwards legitimate requests to internal web servers, thereby hiding the internal server architecture and providing an additional layer of security. This placement aligns with the principle of least exposure, as the DMZ is a semi-trusted network segment designed to host publicly accessible services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In the management network
Why it's wrong here
The management network carries administrative traffic for infrastructure devices; a reverse proxy there cannot serve public web requests and widens administrative exposure. It tempts because management VLANs host jump hosts and monitoring tools, correct for out-of-band administration rather than client-facing services.
- ✓
In the DMZ
Why this is correct
A reverse proxy terminates client connections and forwards requests to backend web servers, so placing it in the DMZ exposes only the proxy to untrusted networks while shielding internal servers, matching the requirement to design a DMZ for the web application.
- ✗
In the database tier
Why it's wrong here
The database tier holds sensitive data and should accept connections only from the application tier; a reverse proxy there cannot receive external client traffic. It tempts because proxies are sometimes deployed near backends for connection pooling, correct when shielding databases from application servers.
- ✗
Inside the internal network
Why it's wrong here
Placing it inside the internal network lets external traffic reach it only after crossing the perimeter, exposing backend systems and defeating DMZ segmentation. It tempts because internal placement suits proxies fronting trusted intranet applications, where no untrusted ingress exists.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.