DS0-001 Database Planning And Deployment Practice Question
A database administrator is deploying a production environment and needs to restrict network access to the database server. Which tool or setting is the first line of defense at the network layer?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewall access control lists
Firewall rules (either host-based or network-based) are the primary way to restrict database access to only authorized application server IPs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Firewall access control lists
Why this is correct
Firewall rules restrict access at the network layer, preventing unauthorized IP connections.
- ✗
SSL/TLS certificates
Why it's wrong here
Certificates encrypt traffic, they do not block connections.
- ✗
Database user permissions
Why it's wrong here
These are application-level access controls, not network-level.
- ✗
Database proxy authentication
Why it's wrong here
Proxies manage connection pooling, not initial network-level filtering.
About these practice questions
One of 216 original DS0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CompTIA exam blueprint
This DS0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DS0-001 exam.