Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)

⚠ Common exam trap

The trap here is choosing convenience-oriented options such as a flat network or disabled host firewalls, which simplify management but directly undermine segmentation and least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall

Defense in depth relies on segmentation and policy enforcement at multiple points. A screened subnet keeps public services away from internal systems, and internal VLANs with firewall-controlled inter-VLAN traffic limit lateral movement. Flat networks, unrestricted DMZ outbound access, and disabled host firewalls all weaken these protections and increase the impact of a compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall

    Why this is correct

    Segmenting internal systems into VLANs and enforcing firewall policy between them prevents a compromised host from freely reaching other systems. Even within the internal network, lateral movement is constrained because traffic between segments must pass through a policy enforcement point. This reduces the blast radius of an incident and supports least-privilege access.

  • ✗

    Allowing all outbound traffic from the DMZ to the internal network

    Why it's wrong here

    Permitting unrestricted outbound traffic from the DMZ to the internal network gives an attacker who compromises a public server a direct path into sensitive systems. Firewall rules should allow only specific, necessary flows from the DMZ, such as database queries to designated hosts. Broad outbound access defeats the purpose of isolating public-facing services and increases the risk of lateral movement.

  • ✗

    Connecting all servers to a single flat VLAN for simplified management

    Why it's wrong here

    A single flat VLAN allows any compromised host to communicate directly with every other host, enabling rapid lateral movement and increasing the impact of an incident. Simplified management does not compensate for the loss of segmentation. This design contradicts the goal of limiting the impact of a compromised host and expands the attack surface rather than reducing it.

  • ✓

    Placing public web servers in a screened subnet (DMZ) with strict firewall rules

    Why this is correct

    A screened subnet isolates public-facing servers from the internal network, so a compromise of a web server does not directly expose internal systems. Firewall rules can restrict traffic from the DMZ to only what is necessary, such as database queries to specific internal hosts. This segmentation limits lateral movement and is a core element of defense in depth.

  • ✗

    Disabling host-based firewalls on internal servers to avoid application conflicts

    Why it's wrong here

    Host-based firewalls provide an additional layer of enforcement directly on the server, restricting which processes can accept connections and from where. Disabling them removes a valuable control and makes it easier for an attacker who gains a foothold to communicate with other systems. Application conflicts should be resolved with specific rules rather than by turning off the firewall entirely.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.