A network administrator needs to host a publicly accessible web server while protecting internal enterprise databases from direct internet exposure. Which network design topology should the administrator implement to place the web server in an isolated perimeter zone between the external internet and the internal private network?
- Demilitarized zone (DMZ)Cevap
- BAir-gapped network
- CFlat internal intranet
- DPartner extranet
Cevap
Demilitarized zone (DMZ)
A demilitarized zone (DMZ) functions as a physical or logical perimeter subnetwork that houses external-facing services such as web, DNS, or mail servers. Placing public resources within a DMZ ensures that internet users can communicate with the web server without gaining direct routing access to sensitive internal servers located behind internal firewalls.
Adım Adım Çözüm
Anahtar Kavram
Demilitarized Zone (DMZ) and Perimeter Isolation