nerdexam
CompTIA

SY0-301 · Question #708

Which of the following BEST describes a demilitarized zone?

The correct answer is A. A buffer zone between protected and unprotected networks. A DMZ (Demilitarized Zone) is a network segment that sits between an untrusted external network (the internet) and a trusted internal network. It hosts publicly accessible services (web servers, mail servers, etc.) while preventing direct access to the internal network. This…

Security architecture

Question

Which of the following BEST describes a demilitarized zone?

Options

  • AA buffer zone between protected and unprotected networks.
  • BA network where all servers exist and are monitored.
  • CA sterile, isolated network segment with access lists.
  • DA private network that is protected by a firewall and a VLAN.

How the community answered

(51 responses)
  • A
    90% (46)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

A DMZ (Demilitarized Zone) is a network segment that sits between an untrusted external network (the internet) and a trusted internal network. It hosts publicly accessible services (web servers, mail servers, etc.) while preventing direct access to the internal network. This 'buffer zone' architecture limits exposure if a DMZ host is compromised. The other options either over-restrict or mischaracterize the DMZ's role - it is not exclusively for monitored servers, not necessarily sterile/isolated, and not synonymous with a VLAN-protected private network.

Topics

#DMZ#network segmentation#perimeter security#network architecture

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice