Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

⚠ Common exam trap

The trap is assuming a VLAN alone provides security isolation — candidates must recognize that a DMZ requires firewall-enforced segmentation between internet, DMZ, and internal networks, not just logical separation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a DMZ

A DMZ (demilitarized zone) is a segmented network that sits between the untrusted internet and the trusted internal LAN, hosting public-facing services like web servers. It allows inbound internet access to the server while firewalls restrict traffic from the DMZ into the internal network, minimizing risk if the server is compromised. This directly satisfies the requirement to isolate the public server from internal networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a DMZ

    Why this is correct

    A DMZ is specifically designed to host public-facing services with controlled access.

  • ✗

    Place the server on the internal LAN with a strong firewall rule

    Why it's wrong here

    Hosting the web server on the internal LAN leaves a publicly reachable host inside the trusted zone, so any compromise provides a pivot to internal systems. A demilitarised zone segments it on a separate subnet where firewall rules restrict traffic both inbound and outbound. Internal placement with firewall rules suits servers accessed only by internal users.

  • ✗

    Use a VLAN to logically separate the server

    Why it's wrong here

    A VLAN provides logical segmentation at layer 2 but does not by itself filter traffic between the server and internal hosts; inter-VLAN routing still permits reachability unless a firewall enforces policy. A demilitarised zone combines subnet separation with firewall control in both directions. VLANs suit separating internal departments that must still communicate under policy.

  • ✗

    Connect the server directly to the internet without firewall

    Why it's wrong here

    Direct internet exposure removes all filtering between the server and external hosts, so compromise of the web service yields unrestricted access rather than containment. A demilitarised zone is the intended architecture, placing the host in a separate subnet governed by firewall rules that permit inbound web traffic while blocking internal reachability. Direct connection suits no production scenario.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.