Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security engineer is designing a network segmentation strategy for a new data center. The engineer wants to ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which of the following controls would BEST achieve this objective?

⚠ Common exam trap

Many candidates confuse detection (IDS) with prevention (firewall rules), or assuming that VLAN separation alone provides sufficient security without firewall filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a firewall to allow only specific, required traffic from the web servers to the database servers.

To prevent direct access from a compromised web server to internal database servers, the engineer should implement a firewall rule that allows only specific, required traffic. This enforces least privilege and segmentation, blocking unauthorized connections. Allowing all traffic, sharing a VLAN, or relying solely on an IDS would not prevent lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a firewall rule that allows all traffic from the DMZ to the internal network.

    Why it's wrong here

    Allowing all traffic from the DMZ to the internal network would provide no segmentation and would enable an attacker who compromises the web server to move laterally to the database servers. This violates the principle of least privilege and defeats the purpose of network segmentation. Thus, it is the opposite of what is needed.

  • ✗

    Place the database servers in the same VLAN as the web servers to simplify management.

    Why it's wrong here

    Placing database servers in the same VLAN as web servers removes any network segmentation between them. If the web server is compromised, the attacker would have direct layer 2 access to the database servers, making lateral movement trivial. This approach increases risk and does not meet the objective of preventing direct access.

  • ✗

    Deploy an intrusion detection system (IDS) between the DMZ and internal network.

    Why it's wrong here

    An IDS can detect malicious traffic but does not prevent it. It is a detective control, not a preventive one. While it can alert on suspicious activity, it would not block an attacker from accessing the database servers. Thus, it does not best achieve the objective of preventing direct access.

  • ✓

    Configure a firewall to allow only specific, required traffic from the web servers to the database servers.

    Why this is correct

    Configuring a firewall to allow only specific, required traffic (e.g., database port) from the web servers to the database servers enforces least privilege and segmentation. This prevents an attacker on a compromised web server from initiating arbitrary connections to the database servers. It is the most effective control to limit lateral movement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.