Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard
A security auditor is reviewing a company's network security posture and finds that many internal systems are directly accessible from the internet, leading to a high risk exposure. The auditor recommends placing all public-facing servers in a separate network zone that acts as a buffer between the internal network and the internet. What is this recommended network zone called?
- ADemilitarized Zone (DMZ)
- BVirtual Local Area Network (VLAN)
- CExtranet
- DIntranet
Show answer & explanationAnswer & explanation
Correct answer: A. Demilitarized Zone (DMZ)
A Demilitarized Zone (DMZ) is a perimeter network that separates an organization's internal network from an untrusted external network (like the internet), typically used to host public-facing servers securely.
Why the other options are wrong
- B. A VLAN segments a network logically but doesn't inherently define a public-facing buffer zone with specific security implications like a DMZ.
- C. An Extranet is an extended intranet that allows controlled access to external partners, not for public-facing servers.
- D. An Intranet is a private internal network, not a public-facing buffer zone.
Demilitarized Zone (DMZ)
A physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted, larger network, usually the Internet.
- Acts as a buffer zone between the internet and the internal network.
- Hosts public-facing servers (web servers, email servers, DNS servers).
- Typically protected by firewalls on both its internet and internal network sides.
- Prevents direct access from the internet to the internal network.
Memory trick: The DMZ is like the castle moat and outer wall, protecting the inner keep (internal network) from direct assault.