ISC2 CC Network Security Practice Question
A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?
⚠ Common exam trap
The trap is selecting 'subnet' or 'VLAN' because they describe network segmentation — candidates must recognize that the question describes a security architecture (DMZ), not just a logical grouping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMZ
A DMZ (demilitarized zone) is a network segment that sits between the internet and the internal LAN, hosting public-facing services while isolating them from internal resources. It is accessible from the internet but separated from the internal network by firewalls, exactly as described. This architecture limits the blast radius if a public server is compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subnet
Why it's wrong here
A subnet is merely an IP addressing subdivision within a network; it provides no enforced isolation boundary between internet-facing and internal systems. It would be correct when segmenting address ranges for routing or size, not when creating a screened zone for public servers.
- ✗
Honeypot
Why it's wrong here
A honeypot is a decoy system designed to attract and observe attackers; it does not host legitimate public services while shielding the internal LAN. It would be correct for threat intelligence or early intrusion detection, not for placing a production web server.
- ✗
VLAN
Why it's wrong here
A VLAN segments traffic logically at layer 2 within shared switching infrastructure; it does not by itself create an internet-facing zone isolated from the internal LAN. It would be correct for separating departments or voice traffic on common hardware.
- ✓
DMZ
Why this is correct
A DMZ is a screened subnet placed between the internet and the internal LAN. It hosts internet-facing services such as the public web server while firewall rules restrict traffic from the DMZ into the internal network, providing the required isolation.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
Key term
DMZ
A DMZ (demilitarized zone) is a network segment that sits between an internal private network and the public internet, hosting publicly accessible services while keeping the internal network isolated.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.