ISC2 CC Network Security Practice Question
A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?
⚠ Common exam trap
The trap is assuming a VLAN alone provides security isolation — candidates must recognize that a DMZ requires firewall-enforced segmentation between internet, DMZ, and internal networks, not just logical separation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a DMZ
A DMZ (demilitarized zone) is a segmented network that sits between the untrusted internet and the trusted internal LAN, hosting public-facing services like web servers. It allows inbound internet access to the server while firewalls restrict traffic from the DMZ into the internal network, minimizing risk if the server is compromised. This directly satisfies the requirement to isolate the public server from internal networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a DMZ
Why this is correct
A DMZ is specifically designed to host public-facing services with controlled access.
- ✗
Place the server on the internal LAN with a strong firewall rule
Why it's wrong here
Hosting the web server on the internal LAN leaves a publicly reachable host inside the trusted zone, so any compromise provides a pivot to internal systems. A demilitarised zone segments it on a separate subnet where firewall rules restrict traffic both inbound and outbound. Internal placement with firewall rules suits servers accessed only by internal users.
- ✗
Use a VLAN to logically separate the server
Why it's wrong here
A VLAN provides logical segmentation at layer 2 but does not by itself filter traffic between the server and internal hosts; inter-VLAN routing still permits reachability unless a firewall enforces policy. A demilitarised zone combines subnet separation with firewall control in both directions. VLANs suit separating internal departments that must still communicate under policy.
- ✗
Connect the server directly to the internet without firewall
Why it's wrong here
Direct internet exposure removes all filtering between the server and external hosts, so compromise of the web service yields unrestricted access rather than containment. A demilitarised zone is the intended architecture, placing the host in a separate subnet governed by firewall rules that permit inbound web traffic while blocking internal reachability. Direct connection suits no production scenario.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
DMZ
A DMZ (demilitarized zone) is a network segment that sits between an internal private network and the public internet, hosting publicly accessible services while keeping the internal network isolated.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.