ISC2 CC Network Security Practice Question
A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)
⚠ Common exam trap
The trap here is choosing convenience-oriented options such as a flat network or disabled host firewalls, which simplify management but directly undermine segmentation and least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall
Defense in depth relies on segmentation and policy enforcement at multiple points. A screened subnet keeps public services away from internal systems, and internal VLANs with firewall-controlled inter-VLAN traffic limit lateral movement. Flat networks, unrestricted DMZ outbound access, and disabled host firewalls all weaken these protections and increase the impact of a compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall
Why this is correct
Segmenting internal systems into VLANs and enforcing firewall policy between them prevents a compromised host from freely reaching other systems. Even within the internal network, lateral movement is constrained because traffic between segments must pass through a policy enforcement point. This reduces the blast radius of an incident and supports least-privilege access.
- ✗
Allowing all outbound traffic from the DMZ to the internal network
Why it's wrong here
Permitting unrestricted outbound traffic from the DMZ to the internal network gives an attacker who compromises a public server a direct path into sensitive systems. Firewall rules should allow only specific, necessary flows from the DMZ, such as database queries to designated hosts. Broad outbound access defeats the purpose of isolating public-facing services and increases the risk of lateral movement.
- ✗
Connecting all servers to a single flat VLAN for simplified management
Why it's wrong here
A single flat VLAN allows any compromised host to communicate directly with every other host, enabling rapid lateral movement and increasing the impact of an incident. Simplified management does not compensate for the loss of segmentation. This design contradicts the goal of limiting the impact of a compromised host and expands the attack surface rather than reducing it.
- ✓
Placing public web servers in a screened subnet (DMZ) with strict firewall rules
Why this is correct
A screened subnet isolates public-facing servers from the internal network, so a compromise of a web server does not directly expose internal systems. Firewall rules can restrict traffic from the DMZ to only what is necessary, such as database queries to specific internal hosts. This segmentation limits lateral movement and is a core element of defense in depth.
- ✗
Disabling host-based firewalls on internal servers to avoid application conflicts
Why it's wrong here
Host-based firewalls provide an additional layer of enforcement directly on the server, restricting which processes can accept connections and from where. Disabling them removes a valuable control and makes it easier for an attacker who gains a foothold to communicate with other systems. Application conflicts should be resolved with specific rules rather than by turning off the firewall entirely.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Policy enforcement
Policy enforcement is the process of implementing and ensuring compliance with defined security rules and configurations across an IT environment.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.