Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A security auditor is reviewing a company's network architecture and notes that critical servers are placed in a network segment that is directly accessible from the internet, without any intermediate security devices. This segment also hosts public-facing web servers. This design poses a significant risk due to the lack of proper isolation. Which network security best practice is being violated?

  1. ARegularly conducting vulnerability assessments.
  2. BImplementing a robust patch management program.
  3. CEnforcing strong password policies for all users.
  4. DUtilizing a Demilitarized Zone (DMZ) for public-facing services.
Show answer & explanation

Correct answer: D. Utilizing a Demilitarized Zone (DMZ) for public-facing services.

A DMZ (Demilitarized Zone) is a critical security best practice for network architecture, specifically designed to host public-facing services (like web servers) in a segregated network segment, isolated from the internal network by firewalls, to protect critical internal resources.

Why the other options are wrong

  • A. Vulnerability assessments identify weaknesses but don't define the architectural best practice itself.
  • B. Patch management is important but doesn't address network segmentation issues.
  • C. Strong password policies are user-level security, not network architecture segmentation.

Demilitarized Zone (DMZ)

A perimeter network segment that separates an organization's internal network from an untrusted external network, usually the internet.

  • Hosts public-facing services like web servers, email servers.
  • Provides an additional layer of security, acting as a buffer zone.
  • Typically protected by two firewalls: one facing the internet, one facing the internal network.

Memory trick: Segment your network like a house: public porch (DMZ), locked doors (firewalls), private rooms (internal).

More Network Security questions