CND Practice Question: Network Security Controls Protocols And Devices
A security architect is designing a high-security DMZ architecture. Public-facing web servers must be isolated from the internal database servers, and an intermediary inspection zone is required. Which design pattern should the architect implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Three-legged firewall architecture creating separate internal, external, and DMZ zones
A three-legged firewall configuration (or dual-firewall DMZ architecture) places public servers in a DMZ zone separate from both the untrusted external internet and the trusted internal LAN, requiring traffic between zones to be inspected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Three-legged firewall architecture creating separate internal, external, and DMZ zones
Why this is correct
A three-legged firewall uses three distinct physical or logical interfaces to isolate the internal network, external network, and DMZ into separate security zones.
- ✗
Placing all web and database servers on the same internal VLAN protected by host firewalls
Why it's wrong here
Placing public-facing web servers on the same VLAN as internal database servers violates defense-in-depth principles by lacking network-level isolation.
- ✗
Single-firewall dual-homed architecture with a software loopback filter
Why it's wrong here
A single firewall with only two interfaces does not provide a true isolated DMZ segment without relying on complex internal VLAN tagging and vulnerability to a single point of failure.
- ✗
Direct flat bridging between the external router and the internal core switch
Why it's wrong here
A flat bridged network exposes internal servers directly to external traffic without any intervening firewall or inspection layer.
About these practice questions
One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.