Courseiva

SSCP Network and Communications Security Practice Question

A network administrator is configuring a demilitarized zone (DMZ) to host a public web server. The server must be accessible from the internet but should be isolated from the internal network. Which of the following is the primary security benefit of placing the web server in a DMZ?

⚠ Common exam trap

Many candidates confuse the DMZ's isolation benefit with other security controls like encryption or patching, which are separate measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It limits the exposure of the internal network if the web server is compromised.

The primary security benefit of a DMZ is to isolate public-facing services from the internal network. If the web server in the DMZ is compromised, the attacker cannot directly access internal systems because firewalls restrict traffic between the DMZ and the internal network. This segmentation limits the damage. Other options describe encryption, prevention, or patching, which are not inherent to a DMZ.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It provides encryption for all traffic to and from the web server.

    Why it's wrong here

    A DMZ does not inherently provide encryption. Encryption would require configuring TLS on the web server or using a VPN. The DMZ is a network segment that adds a layer of isolation, not encryption. While encryption is important, it is not the primary security benefit of a DMZ. The main benefit is to limit the impact of a compromised server.

  • ✗

    It prevents all attacks against the web server by filtering malicious traffic.

    Why it's wrong here

    A DMZ does not prevent all attacks; it is not a magic bullet. It can be combined with firewalls and intrusion prevention systems to filter traffic, but it does not guarantee prevention. The DMZ's primary role is to segment the network so that if the web server is compromised, the attacker cannot directly access the internal network. It does not stop attacks from reaching the server.

  • ✗

    It automatically patches the web server against vulnerabilities.

    Why it's wrong here

    A DMZ does not manage patching or vulnerability remediation. Patching is a separate operational process. The DMZ is a network architecture concept that provides isolation, not automated maintenance. Assuming that a DMZ patches servers would be incorrect and could lead to unpatched systems. The security benefit is segmentation, not system hardening.

  • ✓

    It limits the exposure of the internal network if the web server is compromised.

    Why this is correct

    The primary security benefit of a DMZ is to isolate publicly accessible services from the internal network. If the web server is compromised, the attacker is contained within the DMZ and cannot directly access internal resources. Firewalls between the DMZ and internal network restrict traffic, adding a layer of defense. This segmentation limits the blast radius of a security breach.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.