Courseiva
Security Architecture →easyMultiple Select

SY0-701 DMZ (Demilitarized Zone) Practice Question

A small company is deploying a public web application with a front-end server, an application server, and a database. Which two design choices best reduce exposure of the backend systems? Select two.

⚠ Common exam trap

CompTIA often tests the misconception that placing all servers in a single VLAN with strong passwords is sufficient security, but the trap here is that network segmentation (DMZ and internal subnets) is essential to limit lateral movement, and passwords alone cannot stop an attacker who exploits a vulnerability in the web server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the web server in a DMZ that is reachable from the internet.

Placing the web server in a DMZ (demilitarized zone) allows it to be reachable from the internet while isolating it from the internal network. This design ensures that even if the web server is compromised, an attacker cannot directly access the application server or database, as traffic must pass through a firewall with strict rules. The DMZ acts as a buffer zone, reducing the attack surface of backend systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the web server in a DMZ that is reachable from the internet.

    Why this is correct

    The web server is the system that must face external traffic, so placing it in a DMZ keeps it separate from internal resources. This limits the damage if the public server is compromised.

  • ✗

    Put the database on the same subnet as the web server for faster communication.

    Why it's wrong here

    Placing the database on the same subnet as the web server eliminates network-layer segmentation, meaning an attacker who compromises the front-end can directly access the database without traversing a firewall or ACL. This violates the principle of defence in depth for backend isolation. The temptation arises because co-location reduces latency for database queries, and in a single-tier or tightly controlled internal application where all hosts are equally trusted, this design would be correct for minimising network overhead.

  • ✓

    Place the database on an internal subnet that is not directly reachable from the internet.

    Why this is correct

    Keeping the database on a protected internal subnet reduces direct attack surface. Only approved internal servers should be able to reach it through tightly controlled rules.

  • ✗

    Allow every tier to communicate freely to simplify troubleshooting.

    Why it's wrong here

    Open communication between tiers removes the barriers that segmentation is meant to provide. Troubleshooting convenience should not override basic isolation.

  • ✗

    Use one flat VLAN for all three servers and rely on strong passwords.

    Why it's wrong here

    A flat VLAN offers little containment if one system is compromised. Strong passwords help access control, but they do not replace network segmentation.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.