ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
An organization is deploying a new application that will handle sensitive customer data. The application will reside on a server in a demilitarized zone (DMZ). To protect the internal network from potential compromises of the DMZ server, which network security component should be strategically placed between the DMZ and the internal network?
- ALoad Balancer
- BFirewall
- CIntrusion Detection System (IDS)
- DProxy Server
Show answer & explanationAnswer & explanation
Correct answer: B. Firewall
A firewall is essential for controlling traffic flow and enforcing security policies between different network segments, such as between a DMZ and an internal network. It acts as a primary barrier to prevent unauthorized access.
Why the other options are wrong
- A. A load balancer distributes traffic but does not inherently provide security segmentation or policy enforcement between zones.
- C. An IDS monitors for suspicious activity but does not actively prevent unauthorized traffic from crossing network boundaries.
- D. A proxy server acts as an intermediary for client requests, primarily for caching, filtering content, or anonymity, not for segmenting entire network zones.
Firewall
A network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
- Can be hardware, software, or cloud-based.
- Operates at various layers of the OSI model.
- Essential for network segmentation and perimeter defense.
Memory trick: A 'Firewall' 'Walls' off 'Traffic' between zones.