nerdexam
CompTIA

CAS-001 · Question #437

Company XYZ is building a new customer facing website which must access some corporate resources. The company already has an internal facing web server and a separate server supporting an extranet…

The correct answer is B. Dedicated DMZ network segments. Dedicated DMZ network segments (B) provide the optimal security posture for both servers. Placing each server in its own dedicated DMZ segment isolates them from each other and from the internal network, enforcing strict traffic controls through firewall rules. The…

Technical Integration of Enterprise Components

Question

Company XYZ is building a new customer facing website which must access some corporate resources. The company already has an internal facing web server and a separate server supporting an extranet to which suppliers have access. The extranet web server is located in a network DMZ. The internal website is hosted on a laptop on the internal corporate network. The internal network does not restrict traffic between any internal hosts. Which of the following locations will BEST secure both the intranet and the customer facing website?

Options

  • AThe existing internal network segment
  • BDedicated DMZ network segments
  • CThe existing extranet network segment
  • DA third-party web hosting company

How the community answered

(53 responses)
  • A
    6% (3)
  • B
    81% (43)
  • C
    11% (6)
  • D
    2% (1)

Explanation

Dedicated DMZ network segments (B) provide the optimal security posture for both servers. Placing each server in its own dedicated DMZ segment isolates them from each other and from the internal network, enforcing strict traffic controls through firewall rules. The customer-facing site needs internet exposure but must also access corporate resources - a DMZ with controlled inbound/outbound rules achieves this safely. The existing internal network (A) is too permissive (no traffic restrictions between hosts), exposing corporate systems to compromise. The existing extranet segment (C) is already shared with suppliers, mixing trust boundaries. Third-party hosting (D) introduces third-party risk and reduces control. Dedicated segments give each server isolation appropriate to its trust level.

Topics

#DMZ#network segmentation#web architecture#perimeter security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice