ISC2 CC Network Security Practice Question
An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?
⚠ Common exam trap
Many exam-takers confuse inspection or endpoint protection with access control, when only a source-restricting filter rule actually removes the unauthorized network path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall rule set that permits database access only from the storefront server's address and denies all other sources
Reachability between network segments is governed by filtering rules on a firewall or router ACL, so the only control listed that actually limits which sources may open sessions to the database is a rule permitting the storefront and denying everything else. This enforces least privilege and shrinks the attack surface without disrupting the application's legitimate path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A firewall rule set that permits database access only from the storefront server's address and denies all other sources
Why this is correct
An explicit rule that allows only the storefront server's address to reach the database and denies everything else enforces least privilege at the network layer. It directly implements the stated goal: the application can query the database, while employee workstations are blocked regardless of the protocol or port they attempt.
- ✗
A network-based intrusion prevention system placed inline between the LAN and the screened subnet
Why it's wrong here
An inline IPS inspects traffic for known attack signatures and can drop malicious packets, but it does not enforce which internal hosts may reach a given server. Ordinary workstations sending legitimate-looking queries would still pass, so the IPS does not achieve the segmentation objective of restricting employee access to the database.
- ✗
A host-based antivirus agent installed on each employee workstation
Why it's wrong here
Antivirus software detects malicious code on endpoints but does not govern which network destinations those endpoints may contact. A user running a legitimate database client, or malware that speaks the database protocol, would be unaffected, so this control does not restrict LAN-to-database connectivity as required.
- ✗
Full-disk encryption on the database server's storage volumes
Why it's wrong here
Full-disk encryption protects data if the physical disk or server is stolen, but it has no effect on network reachability. Employee workstations would still be able to open connections to the database service, so this control addresses data at rest rather than the unauthorized network path described in the scenario.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.