ISC2 CC Network Security Practice Question
An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?
⚠ Common exam trap
The trap is confusing VLANs or subnetting with a DMZ — candidates pick VLAN because it 'segments,' but only a DMZ provides firewall-enforced isolation for public-facing services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMZ
A DMZ (Demilitarized Zone) is a segmented network that sits between the internal trusted network and the untrusted internet, specifically designed to host publicly accessible services like web servers while isolating them from internal systems. Firewall rules control traffic between the internet, the DMZ, and the internal network, so if the web server is compromised, the attacker cannot directly reach internal resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Honeypot
Why it's wrong here
A honeypot is a decoy host designed to attract and record attacker activity, not to enforce segmentation or restrict traffic to a production web server. It would add an additional exposed system. Honeypots are the right choice for threat intelligence and early breach detection, not for isolating live services.
- ✗
Subnetting
Why it's wrong here
Subnetting divides address space at layer 3 but provides no traffic-filtering boundary between the internal network and the web server; reachability persists unless a device enforces policy. Subnetting is correct for organising address allocation. Isolation with controlled access demands a firewall-mediated screened subnet.
- ✓
DMZ
Why this is correct
A DMZ sits between the internal network and the internet, exposing the web server to public traffic while firewalls restrict inbound connections to that segment alone. This satisfies the stem's requirement to isolate the server yet permit controlled access, preventing direct reach from the public internet into internal systems.
- ✗
VLAN
Why it's wrong here
A VLAN segments traffic at layer 2 within the same switched infrastructure, so the web server still shares the internal routing domain and cannot be isolated from the private network. VLANs suit departmental separation. Isolating a public-facing host requires a screened subnet with firewall-enforced access control.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
DMZ
A DMZ (demilitarized zone) is a network segment that sits between an internal private network and the public internet, hosting publicly accessible services while keeping the internal network isolated.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.