Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

⚠ Common exam trap

The trap is confusing a DMZ with a VLAN or subnet. While a DMZ can be implemented using VLANs and subnets, the key is its purpose: isolating external-facing services from the internal network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DMZ

A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the internet. It adds an additional layer of security by isolating these services from the internal corporate network. Public web, email, and DNS servers are typically placed in a DMZ to allow external access while protecting the internal network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DMZ

    Why this is correct

    A DMZ (demilitarised zone) sits between the internet-facing perimeter and the internal network, so public-facing servers are reachable from the internet while firewall rules block direct access to internal corporate systems. This satisfies the isolation requirement without exposing the internal network.

  • ✗

    VPN

    Why it's wrong here

    A VPN encrypts traffic between remote endpoints over an untrusted medium; it does not host publicly reachable servers nor isolate them from the internal network. It is tempting because VPNs secure remote access, and would be correct for connecting branch offices or remote workers into the corporate network.

  • ✗

    VLAN

    Why it's wrong here

    A VLAN segments Layer 2 broadcast domains within one physical network, but it does not create an internet-facing perimeter isolated from the corporate LAN; routing between VLANs is trivial without an enforcing firewall. It is tempting because VLANs do separate server traffic, and would suit departmental separation inside a trusted campus.

  • ✗

    Subnet

    Why it's wrong here

    A subnet alone provides no isolation boundary; it is simply an IP address range within a VNet, and internal subnets remain routable to it unless network security groups or firewalls block traffic. It is tempting because subnets segment address space, and would suit organising tiers within one trusted network.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.