nerdexam
Cisco

300-320 · Question #621

An engineer is responsible for the network security design of a small branch. Which security segment does the engineer propose to host the public services of the enterprise such as DNS, email, and…

The correct answer is C. public access DMZ. A DMZ (Demilitarized Zone) is a dedicated network segment designed to host public-facing services such as DNS, email, and web servers. It sits between the external internet and the internal corporate network, providing a controlled security boundary that allows public access…

Security Services

Question

An engineer is responsible for the network security design of a small branch. Which security segment does the engineer propose to host the public services of the enterprise such as DNS, email, and web?

Options

  • Aremote access VPN
  • Bservice provider edge
  • Cpublic access DMZ
  • Dexternal public network

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    86% (25)
  • D
    7% (2)

Explanation

A DMZ (Demilitarized Zone) is a dedicated network segment designed to host public-facing services such as DNS, email, and web servers. It sits between the external internet and the internal corporate network, providing a controlled security boundary that allows public access without exposing sensitive internal resources. The 'public access DMZ' is the standard placement for enterprise services that must be reachable from the internet while remaining isolated from the internal LAN. Remote access VPNs (A) serve authenticated remote users. The service provider edge (B) is the ISP's boundary. The external public network (D) is outside the enterprise's control entirely.

Topics

#DMZ#public services#branch security#network segmentation

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice