ISC2 CC Network Security Practice Question
A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMZ
A DMZ (demilitarized zone) is a segmented network that sits between the internet and the internal network, hosting public-facing servers while allowing controlled access from both sides.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subnetting
Why it's wrong here
Subnetting divides an IP address range into smaller networks, yet without a firewall-enforced perimeter it does not protect internal systems from internet-facing servers. Subnetting is correct when the goal is address management or basic traffic separation, not a screened public zone.
- ✗
Full mesh topology
Why it's wrong here
A full mesh topology connects every node directly to every other, which suits high-availability core networks rather than segregating public-facing servers from internal systems. It provides no security boundary, so the web and email servers would sit exposed alongside internal hosts. A screened subnet (DMZ) is the architecture designed for that separation.
- ✗
Virtual LAN (VLAN)
Why it's wrong here
A VLAN segments traffic logically within one switched network but does not itself create the screened perimeter zone that isolates public-facing servers from internal systems. VLANs are the right choice for separating departmental traffic on shared switching infrastructure.
- ✓
DMZ
Why this is correct
A DMZ sits between the internet-facing firewall and the internal network, so public web and email servers are reachable externally while internal hosts stay shielded. This satisfies the stem's requirement to host public services and protect the internal network, since inbound traffic terminates in the DMZ rather than crossing into the trusted zone.
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.