CAS-004 Security Operations Practice Question
A security engineer is designing a network segmentation strategy for a new data center. The engineer wants to ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which of the following controls would BEST achieve this objective?
⚠ Common exam trap
Many candidates confuse detection (IDS) with prevention (firewall rules), or assuming that VLAN separation alone provides sufficient security without firewall filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a firewall to allow only specific, required traffic from the web servers to the database servers.
To prevent direct access from a compromised web server to internal database servers, the engineer should implement a firewall rule that allows only specific, required traffic. This enforces least privilege and segmentation, blocking unauthorized connections. Allowing all traffic, sharing a VLAN, or relying solely on an IDS would not prevent lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a firewall rule that allows all traffic from the DMZ to the internal network.
Why it's wrong here
Allowing all traffic from the DMZ to the internal network would provide no segmentation and would enable an attacker who compromises the web server to move laterally to the database servers. This violates the principle of least privilege and defeats the purpose of network segmentation. Thus, it is the opposite of what is needed.
- ✗
Place the database servers in the same VLAN as the web servers to simplify management.
Why it's wrong here
Placing database servers in the same VLAN as web servers removes any network segmentation between them. If the web server is compromised, the attacker would have direct layer 2 access to the database servers, making lateral movement trivial. This approach increases risk and does not meet the objective of preventing direct access.
- ✗
Deploy an intrusion detection system (IDS) between the DMZ and internal network.
Why it's wrong here
An IDS can detect malicious traffic but does not prevent it. It is a detective control, not a preventive one. While it can alert on suspicious activity, it would not block an attacker from accessing the database servers. Thus, it does not best achieve the objective of preventing direct access.
- ✓
Configure a firewall to allow only specific, required traffic from the web servers to the database servers.
Why this is correct
Configuring a firewall to allow only specific, required traffic (e.g., database port) from the web servers to the database servers enforces least privilege and segmentation. This prevents an attacker on a compromised web server from initiating arbitrary connections to the database servers. It is the most effective control to limit lateral movement.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.