Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?

⚠ Common exam trap

Many exam-takers confuse inspection or endpoint protection with access control, when only a source-restricting filter rule actually removes the unauthorized network path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall rule set that permits database access only from the storefront server's address and denies all other sources

Reachability between network segments is governed by filtering rules on a firewall or router ACL, so the only control listed that actually limits which sources may open sessions to the database is a rule permitting the storefront and denying everything else. This enforces least privilege and shrinks the attack surface without disrupting the application's legitimate path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A firewall rule set that permits database access only from the storefront server's address and denies all other sources

    Why this is correct

    An explicit rule that allows only the storefront server's address to reach the database and denies everything else enforces least privilege at the network layer. It directly implements the stated goal: the application can query the database, while employee workstations are blocked regardless of the protocol or port they attempt.

  • ✗

    A network-based intrusion prevention system placed inline between the LAN and the screened subnet

    Why it's wrong here

    An inline IPS inspects traffic for known attack signatures and can drop malicious packets, but it does not enforce which internal hosts may reach a given server. Ordinary workstations sending legitimate-looking queries would still pass, so the IPS does not achieve the segmentation objective of restricting employee access to the database.

  • ✗

    A host-based antivirus agent installed on each employee workstation

    Why it's wrong here

    Antivirus software detects malicious code on endpoints but does not govern which network destinations those endpoints may contact. A user running a legitimate database client, or malware that speaks the database protocol, would be unaffected, so this control does not restrict LAN-to-database connectivity as required.

  • ✗

    Full-disk encryption on the database server's storage volumes

    Why it's wrong here

    Full-disk encryption protects data if the physical disk or server is stolen, but it has no effect on network reachability. Employee workstations would still be able to open connections to the database service, so this control addresses data at rest rather than the unauthorized network path described in the scenario.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.