Courseiva

SSCP Network and Communications Security Practice Question

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and an internal database. The architect must ensure that if the web server is compromised, the attacker cannot directly access the internal database. Which DMZ design principle should be applied?

⚠ Common exam trap

The trap here is thinking that a single firewall with multiple interfaces is inherently insecure, but the real issue is the rule set; however, the dual-firewall design provides a clearer separation of duties and is a stronger recommendation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a screened subnet with two firewalls: an external firewall between the internet and DMZ, and an internal firewall between DMZ and internal network.

Using a screened subnet with two firewalls provides defense in depth: the external firewall protects the DMZ from the internet, and the internal firewall protects the internal network from the DMZ. If the web server is compromised, the attacker still faces the internal firewall, which should only allow specific traffic to the database. Placing the database in the DMZ or allowing unrestricted DMZ-to-internal traffic would eliminate this protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a single firewall with three interfaces: internet, DMZ, and internal network, with rules allowing any traffic between DMZ and internal.

    Why it's wrong here

    A single firewall with three interfaces can be secure if rules are properly configured, but allowing any traffic between DMZ and internal defeats the purpose. The requirement is to prevent direct access from a compromised web server to the database. This design would allow such access, so it is incorrect. The firewall rules should restrict DMZ-to-internal traffic to only necessary services.

  • ✗

    Allow all traffic from the DMZ to the internal network to ensure the web server can retrieve data from the database.

    Why it's wrong here

    Allowing all traffic from the DMZ to the internal network is a severe security risk. It would permit an attacker who compromises the web server to move laterally into the internal network and access the database or other resources. This violates least privilege and fails to contain the breach. Specific, limited rules should be used instead.

  • ✓

    Use a screened subnet with two firewalls: an external firewall between the internet and DMZ, and an internal firewall between DMZ and internal network.

    Why this is correct

    A screened subnet with dual firewalls creates two distinct security boundaries. The external firewall controls internet-to-DMZ traffic, while the internal firewall restricts DMZ-to-internal traffic. Even if the web server is compromised, the attacker must bypass the internal firewall to reach the database. This layered defense enforces segmentation and is a best practice for DMZ design.

  • ✗

    Place the database in the same DMZ as the web server to simplify firewall rules.

    Why it's wrong here

    Placing the database in the same DMZ as the web server would allow an attacker who compromises the web server to directly access the database, violating the principle of least privilege and segmentation. This design increases the attack surface and fails to contain a breach. It is insecure and does not meet the requirement to prevent direct access.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.