GSEC Defensible Network Architecture Practice Question
An enterprise network administrator needs to isolate a new public-facing web application so that a compromise of the web server does not immediately expose the internal corporate database and directory services. Which network architecture design pattern provides the most effective defense for this scenario?
⚠ Common exam trap
Examinees often select internal network segmentation or a standard virtual local area network without realizing that a public-facing web tier specifically requires a buffered DMZ architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring a demilitarized zone (DMZ) flanked by firewalls to separate public-facing web assets from internal network resources.
Deploying a demilitarized zone (DMZ) creates a buffered network segment between the untrusted public internet and the trusted internal corporate network. By placing the web server in the DMZ and utilizing firewalls to restrict inbound and outbound traffic flows, administrators successfully contain potential breaches. This defensive architecture stops attackers from pivoting directly into sensitive internal resources following an initial web application compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying the web server on the internal corporate VLAN alongside domain controllers to streamline administrative access and reduce network latency.
Why it's wrong here
Placing public-facing assets directly onto the internal corporate VLAN eliminates critical network boundaries. If an attacker successfully compromises the web server, they immediately gain uninhibited network access to sensitive domain controllers and internal assets without traversing any internal firewalls.
- ✗
Implementing a flat network topology utilizing unmanaged switches to maximize throughput and simplify routing tables for incoming web traffic.
Why it's wrong here
Flat network topologies completely lack internal segmentation controls. Relying on unmanaged switches prevents administrators from enforcing access control lists or firewall policies between network zones, allowing lateral movement across the entire enterprise infrastructure immediately upon initial exploitation.
- ✓
Configuring a demilitarized zone (DMZ) flanked by firewalls to separate public-facing web assets from internal network resources.
Why this is correct
A demilitarized zone architecture establishes a dedicated buffered network segment protected by firewalls. This design ensures that traffic from the internet can only reach designated public services while strictly prohibiting direct connections from the perimeter into the trusted internal network.
- ✗
Connecting the web server directly to the outer provider edge router via a public bridge to bypass internal switching bottlenecks.
Why it's wrong here
Attaching a web server directly to an external provider edge router exposes the host to unfiltered public traffic and removes essential hardware stateful firewall inspection. This approach invites direct infrastructure attacks and lacks any protective layer against modern network-based volumetric threats.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.