Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web server

Public-facing servers like web, mail, and DNS servers are typically placed in a DMZ to isolate them from the internal network. DHCP servers are usually internal, and database servers are kept internal for security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web server

    Why this is correct

    A web server must accept HTTP and HTTPS requests from untrusted internet clients, so it belongs in the DMZ. Hosting it there prevents direct external access to the internal network, satisfying the design constraint of segregating publicly reachable services.

  • ✗

    DHCP server

    Why it's wrong here

    A DHCP server issues addresses to internal clients and, if placed in the DMZ, would either serve untrusted hosts or require broad relay rules exposing the internal network. DHCP belongs on the internal LAN; DMZ hosting suits publicly reachable services like web, mail or DNS servers.

  • ✓

    Mail server

    Why this is correct

    A mail server relays inbound and outbound email from untrusted networks, so it belongs in the DMZ. Placing it there isolates internet-facing SMTP traffic from the internal LAN, satisfying the design constraint of exposing only services requiring external reachability.

  • ✗

    Database server

    Why it's wrong here

    A database server holds sensitive records and belongs in the internal network, reachable from DMZ hosts through controlled firewall rules. Placing it in the DMZ exposes data directly to internet-facing compromise; DMZ placement suits servers that external users must reach, such as web or mail servers.

  • ✓

    DNS server

    Why this is correct

    A DNS server resolving queries for external clients must be reachable from untrusted networks, so it belongs in the DMZ. This isolates name resolution from the internal LAN, satisfying the design constraint of exposing only externally required services.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.