Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A network engineer is designing a network segment for public-facing web servers that need to be accessible from the internet but must be isolated from the internal corporate network to limit potential damage from external attacks. Which network security technology best provides this isolation?

  1. ANetwork Address Translation (NAT)
  2. BDemilitarized Zone (DMZ)
  3. CVirtual Local Area Network (VLAN)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: B. Demilitarized Zone (DMZ)

A Demilitarized Zone (DMZ) is a separate network segment that provides an additional layer of security between a company's internal network and an untrusted network (like the internet). It's specifically designed to host public-facing services while isolating them from the private network.

Why the other options are wrong

  • A. NAT translates private IP addresses to public ones but doesn't inherently create a segregated network zone for security purposes.
  • C. VLANs segment a network logically but don't provide the same level of architectural isolation and security policy enforcement as a DMZ for public-facing servers.
  • D. An IDS monitors traffic for threats but doesn't provide network segmentation or isolation.

Demilitarized Zone (DMZ)

A physical or logical subnetwork that contains and exposes an organization's external-facing services to a larger and untrusted network, usually the internet, while isolating the internal local-area network (LAN).

  • Acts as a buffer zone
  • Hosts public-facing servers (web, email, DNS)
  • Provides an extra layer of security
  • Protects the internal network from direct external access

Memory trick: DMZ: 'D'efense 'M'easures 'Z'one for public servers.

More Security Fundamentals questions