ISC2 Certified in Cybersecurity (CC) Practice Question
In a segmented enterprise network, what is the primary security objective of locating web and mail servers in a demilitarized zone (DMZ) between an external and an internal firewall?
To allow public servers and internal hosts to use the same set of IP addresses.
To restrict direct access from the internet to internal systems if the public servers are breached.
To remove the need for intrusion detection systems on the internal network.
To provide higher bandwidth to public services by bypassing firewall inspection.
A DMZ is a perimeter subnet that contains systems needing direct exposure to the internet, such as web or email servers. Placing these public-facing hosts in the DMZ allows outside users to reach them while shielding the organization's internal LAN. Should an attacker compromise a DMZ system, the second (internal) firewall and network segmentation limit lateral movement, preventing direct access to sensitive internal resources. A DMZ is not designed to boost bandwidth, replace other security controls, or allow shared IP addressing with internal hosts.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a DMZ in network security?
Open an interactive chat with Bash
Why are internal firewalls essential when using a DMZ?
Open an interactive chat with Bash
Can internal and DMZ hosts use the same IP addresses?
Open an interactive chat with Bash
ISC2 Certified in Cybersecurity (CC)
Network Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .