ISC2 CC Network Security Practice Question
A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server
Public-facing servers like web, mail, and DNS servers are typically placed in a DMZ to isolate them from the internal network. DHCP servers are usually internal, and database servers are kept internal for security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Web server
Why this is correct
A web server must accept HTTP and HTTPS requests from untrusted internet clients, so it belongs in the DMZ. Hosting it there prevents direct external access to the internal network, satisfying the design constraint of segregating publicly reachable services.
- ✗
DHCP server
Why it's wrong here
A DHCP server issues addresses to internal clients and, if placed in the DMZ, would either serve untrusted hosts or require broad relay rules exposing the internal network. DHCP belongs on the internal LAN; DMZ hosting suits publicly reachable services like web, mail or DNS servers.
- ✓
Mail server
Why this is correct
A mail server relays inbound and outbound email from untrusted networks, so it belongs in the DMZ. Placing it there isolates internet-facing SMTP traffic from the internal LAN, satisfying the design constraint of exposing only services requiring external reachability.
- ✗
Database server
Why it's wrong here
A database server holds sensitive records and belongs in the internal network, reachable from DMZ hosts through controlled firewall rules. Placing it in the DMZ exposes data directly to internet-facing compromise; DMZ placement suits servers that external users must reach, such as web or mail servers.
- ✓
DNS server
Why this is correct
A DNS server resolving queries for external clients must be reachable from untrusted networks, so it belongs in the DMZ. This isolates name resolution from the internal LAN, satisfying the design constraint of exposing only externally required services.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
Key term
DMZ
A DMZ (demilitarized zone) is a network segment that sits between an internal private network and the public internet, hosting publicly accessible services while keeping the internal network isolated.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.