Courseiva
Security ArchitectureeasyMatchingObjective-mapped

SY0-701 Security Architecture Practice Question

Match each network segment to the best use in a small enterprise.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Network segment for internet-facing services such as a public web proxy or reverse proxy

Segment for internal systems such as databases that should not be directly reachable from the internet

Restricted network used for switch, firewall, and server administration traffic

Internet-only network for visitors and unmanaged devices

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Guest Wi-Fi: Used for external users to access the internet without accessing internal resources.

Each segment serves a specific purpose: guest Wi-Fi for external users, DMZ for public services, internal LAN for daily operations, management for device control, data center for core infrastructure, VPN for secure remote access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Guest Wi-Fi: Used for external users to access the internet without accessing internal resources.

    Why this is correct

    Guest Wi-Fi creates a segmented, untrusted zone for visitors and contractors to reach the internet only. It uses a separate SSID/VLAN with ACLs or a captive portal, and firewall rules block any return traffic to internal resources. Even though it shares the same physical router, routing and L2 isolation keep it from reaching the internal LAN.

  • DMZ: Hosts public-facing services like web servers and email servers.

    Why this is correct

    The DMZ (demilitarized zone) is a buffer network that hosts servers reachable from the internet, such as web, email, and application front ends. Firewalls regulate traffic between internet, DMZ, and internal LAN using different security policies — inbound 443/80 is allowed only to specific DMZ hosts, and those hosts cannot initiate connections into the internal network. This limits exposure if a public server is compromised.

  • Internal LAN: Used for daily operations of internal employees.

    Why this is correct

    The Internal LAN is the trusted zone where employee workstations, printers, and internal databases reside. Unlike the DMZ and guest Wi-Fi, this segment has no direct inbound exposure to the internet, and most traffic is allowed laterally inside the trusted boundary. The organization places its day-to-day computing, data, and authentication traffic here after it passes firewall inspection from other zones.

  • VPN: Used for managing network devices (switches, routers).

    Why it's wrong here

    VPN is not used for managing network devices; that is the role of the management/VLAN segment. A VPN (Virtual Private Network) creates an encrypted tunnel that authenticates remote employees and grants them access to internal resources over the public internet. Device management instead uses protocols like SSH, HTTPS, or SNMP from a hardened admin network, not a remote-access VPN overlay.

  • Management: Provides secure remote access to internal network for employees.

    Why it's wrong here

    The management network segment is dedicated to administrative access to routers, switches, and firewalls using SSH, HTTPS, or console connections, and it is strictly restricted to administrators. It does not provide secure remote access to internal LAN resources for employees — that purpose is filled by a VPN. Interchanging these two terms conflates device control plane access with user data-plane remote connectivity.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.