SY0-301 · Question #8
Which of the following devices would MOST likely have a DMZ interface?
The correct answer is A. Firewall. A firewall is the network device that enforces traffic policy between network segments and is specifically designed to host a DMZ interface alongside its internal and external interfaces. This multi-interface design is a core firewall capability.
Question
Which of the following devices would MOST likely have a DMZ interface?
Options
- AFirewall
- BSwitch
- CLoad balancer
- DProxy
How the community answered
(23 responses)- A87% (20)
- B4% (1)
- C9% (2)
Why each option
A firewall is the network device that enforces traffic policy between network segments and is specifically designed to host a DMZ interface alongside its internal and external interfaces. This multi-interface design is a core firewall capability.
A firewall with three or more interfaces can simultaneously connect to an external untrusted network (internet), an internal trusted network (LAN), and a DMZ segment hosting public-facing servers. The firewall enforces distinct security policies on each interface, isolating DMZ hosts from the internal network while allowing controlled external access - this tri-homed DMZ design is a fundamental firewall architecture.
A switch operates at Layer 2 to forward frames between devices on the same network segment and does not enforce security zone policies or maintain the concept of a DMZ interface.
A load balancer distributes incoming connections across multiple servers for availability and performance; it may reside within a DMZ but does not create or manage DMZ interfaces itself.
A proxy server forwards requests on behalf of clients and may be placed inside a DMZ, but it does not define or control the DMZ network boundary - that is the firewall's role.
Concept tested: Firewall DMZ interface and network segmentation
Source: https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/77007-demystify-pix-dmz.html
Topics
Community Discussion
No community discussion yet for this question.