A CISA is reviewing the network security controls of an organization that utilizes a demilitarized zone (DMZ) for its public-facing web servers. The CISA observes that the firewall rules between the DMZ and the internal production network allow 'ANY' traffic from the web servers to the internal database servers on port 1433 (SQL Server). What is the MOST immediate and significant security concern for the CISA?
- AThe lack of network segmentation within the DMZ itself could lead to lateral movement between web servers.
- BThe use of port 1433 implies cleartext communication, which is a data-in-transit vulnerability.
- CThe web servers in the DMZ are not adequately protected against denial-of-service (DoS) attacks.
- DA compromised web server could directly access and potentially exfiltrate data from internal databases.
Show answer & explanationAnswer & explanation
Correct answer: D. A compromised web server could directly access and potentially exfiltrate data from internal databases.
Allowing 'ANY' traffic, even if restricted to a specific port, from a public-facing DMZ to the internal production network is a critical security flaw. If a web server in the DMZ is compromised, an attacker would have direct, unfiltered access to the internal database, enabling data exfiltration, manipulation, or further internal network penetration. This bypasses the intended security boundary of the DMZ.
Why the other options are wrong
- A. Lateral movement within the DMZ is a concern, but less immediate and significant than direct access from a compromised DMZ server to critical internal production databases.
- B. While port 1433 can be used for cleartext, the primary concern here is the *unrestricted access* from a high-risk zone (DMZ) to a high-value zone (internal database), not necessarily the encryption of that specific traffic.
- C. DoS protection is important, but the firewall rule in question does not directly address DoS mitigation; it addresses traffic flow between zones.
DMZ to Internal Network Firewall Rules
Firewall rules governing traffic flow between the demilitarized zone (DMZ) and the internal trusted network, which should be highly restrictive.
- DMZ servers should only initiate connections to internal systems on specific, required ports and protocols.
- General 'ANY' rules from DMZ to internal are severe security vulnerabilities.
- The principle of least privilege must be strictly applied to DMZ-to-internal communications.
Memory trick: Don't let the 'DMZ' directly 'INVADE' your internal 'KINGDOM'.