Courseiva

GSEC Defensible Network Architecture Practice Question

A junior administrator is asked to make a web server reachable from the internet without exposing the internal database server that the web application uses. The web server sits in a screened subnet, and the database resides on the internal network. Which architecture correctly implements this requirement?

⚠ Common exam trap

The trap here is assuming that database authentication alone is sufficient protection, when network placement and source restriction are what actually limit exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the web server in the screened subnet with inbound HTTP and HTTPS permitted from the internet, and permit only the web server's IP to reach the database on its listening port.

A screened subnet isolates internet-facing services from internal data stores, and restricting database access to the web server's address enforces that boundary at the network layer. Internet clients reach only the web tier, so compromising it does not grant direct access to the database or the broader internal network. Co-locating the database in the screened subnet or opening its listener to any source undermines the isolation the design requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the web server in the screened subnet with inbound HTTP and HTTPS permitted from the internet, and permit only the web server's IP to reach the database on its listening port.

    Why this is correct

    This is the classic screened-subnet design: internet clients reach only the web tier, and the database accepts connections solely from the web server's address on its specific port. If the web server is compromised, the attacker gains no direct path to arbitrary internal hosts, and the database is not exposed to the internet. It satisfies both reachability and isolation.

  • ✗

    Place the web server in the screened subnet and enable a database listener that accepts connections from any source, relying on database authentication to prevent unauthorized access.

    Why it's wrong here

    Allowing the database to accept connections from any source exposes the listener to internet scanning and brute-force or exploit attempts, and authentication is only a single control that can be bypassed by a vulnerability. Network-level restriction to the web server is a defense-in-depth measure that limits exposure even if credentials or the database software are compromised. Open listeners also expand the attack surface unnecessarily.

  • ✗

    Place both the web server and the database in the screened subnet, and permit inbound HTTP and HTTPS from the internet to the web server.

    Why it's wrong here

    Putting the database in the screened subnet places it on the same segment as an internet-facing host, so a web-tier compromise can pivot directly to the database without crossing a firewall. Screened subnets are treated as semi-trusted precisely because they host exposed services; sensitive data stores belong behind an additional internal control, reachable only from the application tier.

  • ✗

    Place the web server on the internal network and publish it through a reverse proxy that forwards requests directly to the database server.

    Why it's wrong here

    Publishing the web server from the internal network violates the screening goal because a compromise of the web tier places the attacker inside the trusted network. Forwarding requests to the database server also exposes the database to internet-originated traffic through the proxy, which is the opposite of the required isolation. The database should never be directly reachable from the internet-facing path.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.