ISC2 Certified in Cybersecurity (CC)Network SecurityHard

A manufacturing company operates several industrial control systems (ICS) that are critical for production and cannot tolerate downtime. To protect these systems from external threats while allowing limited, controlled access for remote monitoring and maintenance, which network security architecture should be implemented to create a demilitarized zone (DMZ) for the ICS?

  1. AScreened Subnet (Triple-Homed) DMZ
  2. BSingle Firewall DMZ
  3. CNo DMZ, direct internet access
  4. DDual-Homed Host DMZ
Show answer & explanation

Correct answer: A. Screened Subnet (Triple-Homed) DMZ

A Screened Subnet (Triple-Homed) DMZ, also known as a three-legged DMZ, uses two firewalls: one between the internet and the DMZ, and another between the DMZ and the internal network. This provides the highest level of security for critical systems like ICS by creating two layers of defense and strict control over traffic flow, ideal for sensitive environments.

Why the other options are wrong

  • B. A single firewall DMZ offers less protection as a compromise of the firewall exposes both DMZ and potentially internal network.
  • C. Direct internet access for ICS is highly insecure and unacceptable for critical infrastructure.
  • D. A dual-homed host DMZ uses a single machine with two network interfaces, which can be a single point of failure and less scalable.

Screened Subnet DMZ (Triple-Homed)

A network architecture that uses two firewalls to create a highly secure demilitarized zone (DMZ), completely isolating it from both the external network (internet) and the internal private network.

  • Employs two firewalls for enhanced security.
  • One firewall faces the internet, the other faces the internal network.
  • DMZ hosts are placed between these two firewalls.
  • Provides maximum isolation for critical services.

Memory trick: A Screened Subnet DMZ is like a 'double-gated fortress', with guards at both the outer and inner walls.

More Network Security questions