CompTIA CySA+ (CS0-003)Security OperationsEasy
A company places its public-facing web server in a separate network segment that is isolated from the internal corporate LAN but still reachable from the internet, with firewall rules restricting traffic between the segment and internal systems. What is this network architecture design called?
- ADemilitarized zone (DMZ)
- BAir-gapped network
- CSoftware-defined perimeter
- DVirtual private network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: A. Demilitarized zone (DMZ)
A DMZ is a segmented network that hosts internet-facing services while restricting direct access to the internal LAN, limiting the blast radius if the public server is compromised.
Why the other options are wrong
- B. An air-gapped network has no connection to the internet at all.
- C. Software-defined perimeter is an access control model, not a physical/logical segment for public servers.
- D. A VPN provides encrypted remote connectivity, not network segmentation for public servers.
Demilitarized Zone (DMZ)
A network segment placed between the internet and the internal LAN that hosts public-facing services while limiting direct access to internal resources.
- Reduces attack surface exposure to internal network
- Typically bounded by firewalls on both sides
- Common DMZ hosts: web, mail, DNS servers
Memory trick: DMZ = the buffer zone between enemy (internet) and home (LAN).