nerdexam
CompTIA

N10-009 · Question #326

A network engineer needs to add a boundary network to isolate and separate the internal network from the public-facing internet. Which of the following security defense solutions would best…

The correct answer is D. Screened subnet. A screened subnet (also known as a demilitarized zone (DMZ)) is a security architecture that isolates and separates the internal network from the public-facing internet by placing public-facing services (such as web servers, email servers, and VPN gateways) in an intermediate…

Submitted by salim_om· Mar 6, 2026Network Security

Question

A network engineer needs to add a boundary network to isolate and separate the internal network from the public-facing internet. Which of the following security defense solutions would best accomplish this task?

Options

  • ATrusted zones
  • BURL filtering
  • CACLs
  • DScreened subnet

How the community answered

(49 responses)
  • A
    10% (5)
  • B
    6% (3)
  • C
    2% (1)
  • D
    82% (40)

Explanation

A screened subnet (also known as a demilitarized zone (DMZ)) is a security architecture that isolates and separates the internal network from the public-facing internet by placing public-facing services (such as web servers, email servers, and VPN gateways) in an intermediate security zone. This prevents direct access to the internal network, reducing the risk of attacks. A screened subnet typically involves firewalls on both sides, with: One firewall facing the public internet Another firewall protecting the internal network

Community Discussion

No community discussion yet for this question.

Full N10-009 Practice