ISC2 Certified in Cybersecurity (CC)Network SecurityEasy
A small business is setting up its first public-facing web server. To protect its internal network from direct attacks while still allowing external users to access the web server, which network security zone should the web server be placed in?
- AProduction Network
- BDemilitarized Zone (DMZ)
- CInternal Network
- DGuest Network
Show answer & explanationAnswer & explanation
Correct answer: B. Demilitarized Zone (DMZ)
The Demilitarized Zone (DMZ) is specifically designed to host public-facing services, separating them from the internal network to enhance security. This placement limits the impact of a successful attack on the web server to the DMZ itself, preventing it from directly compromising internal resources.
Why the other options are wrong
- A. While a web server is part of a production environment, 'Production Network' is too broad and doesn't specify the security segmentation needed for public access.
- C. Placing a public-facing server directly in the internal network exposes critical internal resources to external threats.
- D. A guest network is typically for temporary, untrusted user access and not for hosting production public services.
Demilitarized Zone (DMZ)
A physical or logical subnetwork that contains and exposes an organization's external-facing services to a larger untrusted network, usually the internet.
- Acts as a buffer zone between the internet and the internal network.
- Hosts public-facing servers (e.g., web, email, DNS).
- Protects internal network resources from direct external attacks.
Memory trick: DMZ is the 'doorway' for public access, keeping the house safe.