SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium

A security engineer is designing a secure network architecture. The design includes a perimeter network (DMZ) to host public-facing servers, which must be accessible from the internet but isolated from the internal corporate network. What is the primary purpose of implementing a DMZ in this scenario?

  1. ATo encrypt all traffic between public-facing servers and the internet.
  2. BTo perform deep packet inspection on all outbound internet traffic.
  3. CTo provide a buffer zone for public-facing services, isolating them from the internal network.
  4. DTo enforce strict access controls for internal users accessing public resources.
Show answer & explanation

Correct answer: C. To provide a buffer zone for public-facing services, isolating them from the internal network.

A Demilitarized Zone (DMZ) creates a separate network segment that acts as a buffer between the internet and the internal network. This allows public-facing servers to be accessible from the internet without directly exposing the internal network to external threats.

Why the other options are wrong

  • A. Encryption is a separate security measure, not the primary purpose of a DMZ's architectural design. Firewalls handle this.
  • B. Deep packet inspection is a function of firewalls or IPS/IDS, not the inherent architectural purpose of a DMZ itself.
  • D. While a DMZ can involve access controls, its primary role isn't specifically for internal users accessing public resources but for external users accessing public resources without risking the internal network.

Demilitarized Zone (DMZ)

A perimeter network that protects an organization's internal local area network (LAN) from untrusted traffic, typically from the internet.

  • Acts as a buffer zone.
  • Hosts public-facing servers (e.g., web, email).
  • Separated from internal and external networks by firewalls.

Memory trick: Segments Protect Zones.

More Network and Communications Security questions