ISC2 CC Network Security Practice Question
A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)
⚠ Common exam trap
The trap here is the 'convenience' distractor — options that promise easier access (allow all inbound, unrestricted DMZ-to-LAN) sound operationally appealing but violate the core DMZ principle of least privilege and defense in depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place only public-facing servers (e.g., web, email) in the DMZ.
Option A is correct because a DMZ is specifically designed to host public-facing services such as web and email servers, isolating them from the trusted internal network so that a compromise of these exposed hosts does not directly expose internal assets. Option B is correct because a firewall (or multiple firewalls) must mediate and filter traffic among the internet, the DMZ, and the internal network, enforcing distinct security policies for each zone rather than allowing unrestricted flows. Option E is correct because inbound traffic to the DMZ should be limited to only the ports and protocols required by the hosted services — for example TCP 80/443 for HTTP/HTTPS and TCP 25 for SMTP — following the principle of least privilege to minimize the attack surface. Option C is incorrect because unrestricted DMZ-to-internal communication defeats the purpose of segmentation and would let a compromised DMZ host pivot directly into the internal network. Option D is incorrect because allowing all inbound internet traffic to the DMZ exposes unnecessary ports and services, greatly increasing the risk of exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place only public-facing servers (e.g., web, email) in the DMZ.
Why this is correct
Segregating public-facing web and email servers into the DMZ keeps them off the internal network, so a compromise cannot directly pivot inward. This satisfies the DMZ design constraint that only externally reachable services reside in that screened subnet.
- ✓
Use a firewall to control traffic between the internet, DMZ, and internal network.
Why this is correct
A firewall enforces traffic separation across the three zones, satisfying the DMZ requirement that internet-facing servers must not reach the internal network directly. Rules permit inbound HTTP/SMTP to the DMZ hosts while blocking DMZ-initiated connections inward, containing any compromised web or email server.
- ✗
Configure the DMZ to communicate directly with the internal network without restrictions.
Why it's wrong here
Unrestricted DMZ-to-internal communication lets a compromised web or email server pivot straight into the trusted network, removing the containment a DMZ provides. It is tempting because it avoids writing firewall rules for each required service, and would fit a flat lab segment with no sensitive internal assets.
- ✗
Allow all inbound traffic to the DMZ from the internet for ease of access.
Why it's wrong here
Permitting all inbound internet traffic to the DMZ exposes the web and email servers to unrestricted scanning and exploitation, defeating the purpose of segmenting them. It is tempting as a quick way to guarantee service reachability, and would suit a lab or honeypot where exposure is deliberate and contained.
- ✓
Restrict inbound traffic to only required services (e.g., HTTP, SMTP).
Why this is correct
Permitting only the ports the hosted services require — HTTP/HTTPS for the web server, SMTP for the email server — minimises the exposed attack surface. This satisfies the DMZ best practice of least-privilege exposure, blocking all other inbound traffic to the public-facing hosts.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.