Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

⚠ Common exam trap

The trap is confusing VLANs or subnetting with a DMZ — candidates pick VLAN because it 'segments,' but only a DMZ provides firewall-enforced isolation for public-facing services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DMZ

A DMZ (Demilitarized Zone) is a segmented network that sits between the internal trusted network and the untrusted internet, specifically designed to host publicly accessible services like web servers while isolating them from internal systems. Firewall rules control traffic between the internet, the DMZ, and the internal network, so if the web server is compromised, the attacker cannot directly reach internal resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Honeypot

    Why it's wrong here

    A honeypot is a decoy host designed to attract and record attacker activity, not to enforce segmentation or restrict traffic to a production web server. It would add an additional exposed system. Honeypots are the right choice for threat intelligence and early breach detection, not for isolating live services.

  • ✗

    Subnetting

    Why it's wrong here

    Subnetting divides address space at layer 3 but provides no traffic-filtering boundary between the internal network and the web server; reachability persists unless a device enforces policy. Subnetting is correct for organising address allocation. Isolation with controlled access demands a firewall-mediated screened subnet.

  • ✓

    DMZ

    Why this is correct

    A DMZ sits between the internal network and the internet, exposing the web server to public traffic while firewalls restrict inbound connections to that segment alone. This satisfies the stem's requirement to isolate the server yet permit controlled access, preventing direct reach from the public internet into internal systems.

  • ✗

    VLAN

    Why it's wrong here

    A VLAN segments traffic at layer 2 within the same switched infrastructure, so the web server still shares the internal routing domain and cannot be isolated from the private network. VLANs suit departmental separation. Isolating a public-facing host requires a screened subnet with firewall-enforced access control.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.