ISC2 CC Network Security Practice Question
A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?
⚠ Common exam trap
Many candidates confuse a DMZ with a generic subnet or VLAN — candidates pick 'subnet' because a DMZ is technically implemented as one, but the question is testing the security concept of an isolated internet-facing buffer zone, not the addressing construct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMZ
A DMZ (demilitarized zone) is a perimeter network segment that hosts internet-facing services such as web and email servers while keeping them isolated from the trusted internal LAN. It creates a buffer zone so that if a public-facing server is compromised, the attacker cannot directly pivot into internal systems. This matches the scenario exactly: internet-accessible but separated from the internal network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VLAN
Why it's wrong here
A VLAN segments traffic logically at layer 2 within the same switched infrastructure, so hosts remain on the internal network rather than being isolated from it. VLANs are correct when the goal is to separate departments or broadcast domains, not to expose servers to the internet.
- ✓
DMZ
Why this is correct
A DMZ is a perimeter subnetwork exposing public-facing services such as web and email servers to the internet while firewall rules block direct access to the internal LAN, limiting exposure if those hosts are compromised.
- ✗
Honeypot
Why it's wrong here
A honeypot is a decoy system deliberately exposed to attract and observe attackers, not a production segment hosting live web and email servers. It would be correct if the requirement were to detect or study intrusion attempts rather than to serve legitimate public traffic.
- ✗
Subnet
Why it's wrong here
A subnet is an IP addressing subdivision within a network, defined by a mask, and carries no inherent isolation from the internal LAN or internet exposure. It would be the answer when the question asked how to divide an address range for routing or address allocation.
Go deeper
Related to this question
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.