Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

⚠ Common exam trap

The trap is selecting 'subnet' or 'VLAN' because they describe network segmentation — candidates must recognize that the question describes a security architecture (DMZ), not just a logical grouping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DMZ

A DMZ (demilitarized zone) is a network segment that sits between the internet and the internal LAN, hosting public-facing services while isolating them from internal resources. It is accessible from the internet but separated from the internal network by firewalls, exactly as described. This architecture limits the blast radius if a public server is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Subnet

    Why it's wrong here

    A subnet is merely an IP addressing subdivision within a network; it provides no enforced isolation boundary between internet-facing and internal systems. It would be correct when segmenting address ranges for routing or size, not when creating a screened zone for public servers.

  • ✗

    Honeypot

    Why it's wrong here

    A honeypot is a decoy system designed to attract and observe attackers; it does not host legitimate public services while shielding the internal LAN. It would be correct for threat intelligence or early intrusion detection, not for placing a production web server.

  • ✗

    VLAN

    Why it's wrong here

    A VLAN segments traffic logically at layer 2 within shared switching infrastructure; it does not by itself create an internet-facing zone isolated from the internal LAN. It would be correct for separating departments or voice traffic on common hardware.

  • ✓

    DMZ

    Why this is correct

    A DMZ is a screened subnet placed between the internet and the internal LAN. It hosts internet-facing services such as the public web server while firewall rules restrict traffic from the DMZ into the internal network, providing the required isolation.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.