Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

A firm's network is divided so that its public web server sits in a separate zone, reachable from the internet but isolated by a firewall from the internal database network. Even if the web server is compromised, the attacker cannot directly reach internal systems. Which design is this, and what is its main purpose?

This is a demilitarized zone (DMZ). Public-facing servers are placed in a separate screened subnet behind firewall controls, so that if one is compromised the attacker still cannot directly reach the internal database network. Its purpose is limiting exposure of internal systems.

  1. ADemilitarized zone (DMZ), to limit exposure of internal network by isolating public-facing servicesCorrect
  2. BVirtual LAN trunking, to increase bandwidth between switches
  3. CNetwork address translation, to encrypt packets leaving the firm
  4. DLoad balancing cluster, to distribute requests across several servers

Explanation

A DMZ is a screened subnet hosting public-facing services, separated by firewalls from the internal network, so a breach of the web server does not give direct internal access. VLAN trunking, NAT and load balancing serve different purposes and NAT does not encrypt.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions