CompTIA Network+ (N10-009)Network SecurityMedium
A company needs to host a public-facing web server that is reachable from the internet while ensuring that a compromise of that server does not give an attacker direct access to the internal LAN. Which architecture should be implemented?
- ASingle flat VLAN with an ACL
- BScreened subnet (DMZ) between two firewalls
- CSite-to-site VPN tunnel
- DPrivate VLAN with protected ports
Show answer & explanationAnswer & explanation
Correct answer: B. Screened subnet (DMZ) between two firewalls
A screened subnet (DMZ) places public-facing servers in a segment isolated between an external and internal firewall, so external users can reach the server without gaining a path into the protected internal network. Private VLANs and flat VLANs don't provide the same internet-facing isolation from the core LAN.
Why the other options are wrong
- A. A flat VLAN with only an ACL still exposes the LAN if the server is compromised.
- C. A VPN secures remote access, not public server exposure.
- D. Private VLANs isolate hosts within the same subnet, not internet-facing servers from the LAN.
Screened Subnet (DMZ)
A network segment placed between an external and internal firewall that hosts public-facing servers, isolating them from the internal LAN.
- Also called a DMZ (demilitarized zone)
- Typically bounded by two firewalls or one firewall with three interfaces
- Limits attacker's lateral movement if a public server is compromised
Memory trick: The DMZ is the castle's outer courtyard—visitors allowed, but the keep stays locked.