ISC2 CC Network Security Practice Question
A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)
⚠ Common exam trap
The trap is choosing 'simplify management' options (like same VLAN or allow all outbound) because they sound operationally convenient, but the CC exam tests security-first principles: segmentation, least privilege, and logging are always preferred over convenience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a firewall to control traffic between the DMZ and internal network.
Option A is correct because a firewall must mediate traffic between the DMZ and the internal network, enforcing rules that prevent a compromised DMZ host from directly reaching internal resources; this segmentation is a core DMZ security control. Option C is correct because placing each server type (web, email, DNS) on its own VLAN segments the DMZ and limits lateral movement if one server is compromised, so an attacker cannot easily pivot to the other servers. Option B is incorrect because putting all DMZ servers on one flat VLAN increases the attack surface and enables lateral movement between them. Option D is incorrect because unrestricted outbound traffic from the DMZ enables data exfiltration, command-and-control callbacks, and abuse of the servers; outbound traffic should be restricted to required destinations and ports. Option E is incorrect because disabling logging removes the audit trail needed for detecting and investigating intrusions, and logging is a required security control, not an optional resource saving.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a firewall to control traffic between the DMZ and internal network.
Why this is correct
A firewall between the DMZ and internal network enforces traffic control, satisfying the requirement to contain compromised DMZ hosts. It restricts inbound access so internet-facing servers cannot freely reach internal resources, applying least privilege and limiting lateral movement if the web, email, or DNS server is breached.
- ✗
Place all DMZ servers on the same VLAN to simplify management.
Why it's wrong here
A single VLAN lets a compromise of the web server reach the email and DNS servers at layer 2 without crossing a filtering device, so no inter-server segmentation exists. It is tempting because one VLAN simplifies addressing and switch configuration, and it would be correct for servers of identical trust level requiring no mutual isolation.
- ✓
Implement separate VLANs for each type of server to limit lateral movement.
Why this is correct
Segmenting each server type onto its own VLAN enforces Layer 2 isolation, so a compromised web server cannot reach the email or DNS servers directly. This satisfies the stem's requirement to limit lateral movement within the DMZ, since broadcast domains and inter-VLAN traffic are constrained by routing and firewall policy rather than shared adjacency.
- ✗
Allow all outbound traffic from the DMZ to the internet for ease of use.
Why it's wrong here
Permitting all outbound traffic lets a compromised DMZ host beacon to command-and-control infrastructure and exfiltrate data, defeating the containment a DMZ provides. It is tempting because unrestricted egress avoids troubleshooting broken updates, and it would be acceptable on an isolated test network with no sensitive internal reachability.
- ✗
Disable logging on DMZ devices to conserve resources.
Why it's wrong here
Disabling logging removes the audit trail needed to detect and investigate intrusions against the internet-facing servers, contradicting DMZ monitoring requirements. It is tempting because logs consume storage and CPU, and disabling them would be defensible on a lab or performance-testing segment where forensic evidence is not required.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.