ISC2 CC Network Security Practice Question
An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?
⚠ Common exam trap
The trap is confusing a DMZ with a VLAN or subnet. While a DMZ can be implemented using VLANs and subnets, the key is its purpose: isolating external-facing services from the internal network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMZ
A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the internet. It adds an additional layer of security by isolating these services from the internal corporate network. Public web, email, and DNS servers are typically placed in a DMZ to allow external access while protecting the internal network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DMZ
Why this is correct
A DMZ (demilitarised zone) sits between the internet-facing perimeter and the internal network, so public-facing servers are reachable from the internet while firewall rules block direct access to internal corporate systems. This satisfies the isolation requirement without exposing the internal network.
- ✗
VPN
Why it's wrong here
A VPN encrypts traffic between remote endpoints over an untrusted medium; it does not host publicly reachable servers nor isolate them from the internal network. It is tempting because VPNs secure remote access, and would be correct for connecting branch offices or remote workers into the corporate network.
- ✗
VLAN
Why it's wrong here
A VLAN segments Layer 2 broadcast domains within one physical network, but it does not create an internet-facing perimeter isolated from the corporate LAN; routing between VLANs is trivial without an enforcing firewall. It is tempting because VLANs do separate server traffic, and would suit departmental separation inside a trusted campus.
- ✗
Subnet
Why it's wrong here
A subnet alone provides no isolation boundary; it is simply an IP address range within a VNet, and internal subnets remain routable to it unless network security groups or firewalls block traffic. It is tempting because subnets segment address space, and would suit organising tiers within one trusted network.
Visual reference
Go deeper
Related to this question
Learn chapter
Logical Access Controls
Key term
DMZ
A DMZ (demilitarized zone) is a network segment that sits between an internal private network and the public internet, hosting publicly accessible services while keeping the internal network isolated.
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.