GAQM
CPEH-001 · Question #120
Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ports, which can have direct internet…
The correct answer is C. Bob is totally wrong. DMZ is always relevant when the company has internet servers and workstations. See the full explanation below for the reasoning.
Question
Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ports, which can have direct internet access, and block the access to workstations. Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA. In this context, what can you say?
Options
- ABob can be right since DMZ does not make sense when combined with stateless firewalls
- BBob is partially right. He does not need to separate networks if he can create rules by destination IPs,
- CBob is totally wrong. DMZ is always relevant when the company has internet servers and workstations
- DBob is partially right. DMZ does not make sense when a stateless firewall is available
How the community answered
(23 responses)- A13% (3)
- B4% (1)
- C78% (18)
- D4% (1)
Community Discussion
No community discussion yet for this question.