ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

An organization is deploying a new application that will handle sensitive customer data. The application will reside on a server in a demilitarized zone (DMZ). To protect the internal network from potential compromises of the DMZ server, which network security component should be strategically placed between the DMZ and the internal network?

  1. ALoad Balancer
  2. BFirewall
  3. CIntrusion Detection System (IDS)
  4. DProxy Server
Show answer & explanation

Correct answer: B. Firewall

A firewall is essential for controlling traffic flow and enforcing security policies between different network segments, such as between a DMZ and an internal network. It acts as a primary barrier to prevent unauthorized access.

Why the other options are wrong

  • A. A load balancer distributes traffic but does not inherently provide security segmentation or policy enforcement between zones.
  • C. An IDS monitors for suspicious activity but does not actively prevent unauthorized traffic from crossing network boundaries.
  • D. A proxy server acts as an intermediary for client requests, primarily for caching, filtering content, or anonymity, not for segmenting entire network zones.

Firewall

A network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.

  • Can be hardware, software, or cloud-based.
  • Operates at various layers of the OSI model.
  • Essential for network segmentation and perimeter defense.

Memory trick: A 'Firewall' 'Walls' off 'Traffic' between zones.

More Communication and Network Security questions