CompTIA Network+ (N10-009)Network SecurityMedium

A company needs to host a public-facing web server that is reachable from the internet while ensuring that a compromise of that server does not give an attacker direct access to the internal LAN. Which architecture should be implemented?

  1. ASingle flat VLAN with an ACL
  2. BScreened subnet (DMZ) between two firewalls
  3. CSite-to-site VPN tunnel
  4. DPrivate VLAN with protected ports
Show answer & explanation

Correct answer: B. Screened subnet (DMZ) between two firewalls

A screened subnet (DMZ) places public-facing servers in a segment isolated between an external and internal firewall, so external users can reach the server without gaining a path into the protected internal network. Private VLANs and flat VLANs don't provide the same internet-facing isolation from the core LAN.

Why the other options are wrong

  • A. A flat VLAN with only an ACL still exposes the LAN if the server is compromised.
  • C. A VPN secures remote access, not public server exposure.
  • D. Private VLANs isolate hosts within the same subnet, not internet-facing servers from the LAN.

Screened Subnet (DMZ)

A network segment placed between an external and internal firewall that hosts public-facing servers, isolating them from the internal LAN.

  • Also called a DMZ (demilitarized zone)
  • Typically bounded by two firewalls or one firewall with three interfaces
  • Limits attacker's lateral movement if a public server is compromised

Memory trick: The DMZ is the castle's outer courtyard—visitors allowed, but the keep stays locked.

More Network Security questions