Soru

Zorluk: KolaySecure Network Design and Segmentation

A network administrator needs to host a publicly accessible web server while protecting internal enterprise databases from direct internet exposure. Which network design topology should the administrator implement to place the web server in an isolated perimeter zone between the external internet and the internal private network?

  1. Demilitarized zone (DMZ)Cevap
  2. B
    Air-gapped network
  3. C
    Flat internal intranet
  4. D
    Partner extranet

Cevap

Demilitarized zone (DMZ)
A demilitarized zone (DMZ) functions as a physical or logical perimeter subnetwork that houses external-facing services such as web, DNS, or mail servers. Placing public resources within a DMZ ensures that internet users can communicate with the web server without gaining direct routing access to sensitive internal servers located behind internal firewalls.

Adım Adım Çözüm

1
Identify the requirement to host an internet-facing application while shielding private database infrastructure.
Determine that a boundary network is needed between untrusted external traffic and trusted internal resources.
Public-facing hosts have a higher risk of attack and must be separated from sensitive internal servers.
2
Select the appropriate network isolation architecture.
Choose a Demilitarized Zone (DMZ) topology.
A DMZ enforces traffic boundaries via firewalls so that external requests reach the web server without direct network access to the internal network.

Anahtar Kavram

Demilitarized Zone (DMZ) and Perimeter Isolation
Bu soruyu puanla