Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A security auditor is reviewing a company's network architecture and notes that critical servers are placed in a network segment that is directly accessible from the internet, without any intermediate security devices. This segment also hosts public-facing web servers. This design poses a significant risk due to the lack of proper isolation. Which network security best practice is being violated?
- ARegularly conducting vulnerability assessments.
- BImplementing a robust patch management program.
- CEnforcing strong password policies for all users.
- DUtilizing a Demilitarized Zone (DMZ) for public-facing services.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilizing a Demilitarized Zone (DMZ) for public-facing services.
A DMZ (Demilitarized Zone) is a critical security best practice for network architecture, specifically designed to host public-facing services (like web servers) in a segregated network segment, isolated from the internal network by firewalls, to protect critical internal resources.
Why the other options are wrong
- A. Vulnerability assessments identify weaknesses but don't define the architectural best practice itself.
- B. Patch management is important but doesn't address network segmentation issues.
- C. Strong password policies are user-level security, not network architecture segmentation.
Demilitarized Zone (DMZ)
A perimeter network segment that separates an organization's internal network from an untrusted external network, usually the internet.
- Hosts public-facing services like web servers, email servers.
- Provides an additional layer of security, acting as a buffer zone.
- Typically protected by two firewalls: one facing the internet, one facing the internal network.
Memory trick: Segment your network like a house: public porch (DMZ), locked doors (firewalls), private rooms (internal).