CompTIA Security+ (SY0-701)Security ArchitectureMedium

A network architect is designing a corporate network and wants to place a public-facing web server so that it is reachable from the internet but isolated from the internal LAN if compromised. Which architecture BEST achieves this?

  1. APlacing the server on the internal VLAN with the database servers
  2. BPlacing the server in a screened subnet (DMZ) between two firewalls
  3. CPlacing the server directly on the internet with a public IP and no firewall
  4. DPlacing the server on the same segment as the guest Wi-Fi network
Show answer & explanation

Correct answer: B. Placing the server in a screened subnet (DMZ) between two firewalls

A screened subnet (DMZ) sits between an external and internal firewall, allowing internet access to the public server while restricting traffic from reaching the internal network if the server is compromised.

Why the other options are wrong

  • A. Placing it with internal databases exposes sensitive internal systems directly to any compromise of the web server.
  • C. No firewall protection leaves the server and any pivoted attacker with unrestricted exposure.
  • D. Guest Wi-Fi segments are for untrusted client devices, not for hosting servers meant to be reached from the internet.

Screened Subnet (DMZ)

A network segment positioned between external and internal firewalls that hosts public-facing services, isolating them from the trusted internal network.

  • Also called demilitarized zone
  • Typically bounded by two firewalls or one firewall with three interfaces
  • Limits blast radius if a public server is compromised

Memory trick: DMZ is the buffer zone between enemy (internet) and home (LAN).

More Security Architecture questions