Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard

A security auditor is reviewing a company's network security posture and finds that many internal systems are directly accessible from the internet, leading to a high risk exposure. The auditor recommends placing all public-facing servers in a separate network zone that acts as a buffer between the internal network and the internet. What is this recommended network zone called?

  1. ADemilitarized Zone (DMZ)
  2. BVirtual Local Area Network (VLAN)
  3. CExtranet
  4. DIntranet
Show answer & explanation

Correct answer: A. Demilitarized Zone (DMZ)

A Demilitarized Zone (DMZ) is a perimeter network that separates an organization's internal network from an untrusted external network (like the internet), typically used to host public-facing servers securely.

Why the other options are wrong

  • B. A VLAN segments a network logically but doesn't inherently define a public-facing buffer zone with specific security implications like a DMZ.
  • C. An Extranet is an extended intranet that allows controlled access to external partners, not for public-facing servers.
  • D. An Intranet is a private internal network, not a public-facing buffer zone.

Demilitarized Zone (DMZ)

A physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted, larger network, usually the Internet.

  • Acts as a buffer zone between the internet and the internal network.
  • Hosts public-facing servers (web servers, email servers, DNS servers).
  • Typically protected by firewalls on both its internet and internal network sides.
  • Prevents direct access from the internet to the internal network.

Memory trick: The DMZ is like the castle moat and outer wall, protecting the inner keep (internal network) from direct assault.

More Network Security questions