220-1102 exam dumps

220-1102 practice question 543 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 543

Single answerScreened subnet

A small company hosts a public web server that customers must access from the internet, but the internal file server and employee workstations must remain isolated from direct external connections. The technician proposes placing the web server on a screened subnet. Which configuration best meets this requirement?

  1. A

    Place the web server on a separate network segment between the internet and the internal LAN, and use firewall rules to allow only required public traffic to that segment

  2. B

    Connect the web server directly to the internal LAN and allow inbound TCP 80 and 443 from the internet to the server

  3. C

    Install antivirus on the web server and keep it on the same subnet as employee PCs, since malware protection replaces the need for network isolation

  4. D

    Disable all inbound traffic from the internet and require customers to use a VPN before viewing the company website

Show answer and explanation

Correct answer: A

Explanation

A screened subnet is a security architecture used to place public-facing resources, such as web, mail, or DNS servers, in an isolated network zone between the internet and the private LAN. In many environments, this zone is called a DMZ. The primary best practice is to allow only the minimum required traffic from the internet to the public server and tightly restrict any traffic between that server and the internal network. This reduces the risk that a compromise of the public server will lead directly to compromise of internal systems. This approach aligns with common security best practices such as network segmentation, least privilege, and defense in depth, and is consistent with guidance from major security frameworks and vendor firewall documentation.

  • A. Correct.

    Correct. A screened subnet, commonly implemented as a DMZ, places public-facing systems such as web servers on a separate network segment isolated from the internal network. Firewalls are then used to permit only necessary inbound traffic, such as HTTP or HTTPS, to the public server while restricting access to the internal LAN. This is the standard design goal of a screened subnet.

  • B. Incorrect.

    Incorrect. Although allowing only ports 80 and 443 may seem limited, placing the public web server directly on the internal LAN exposes the internal network to additional risk if the server is compromised. A screened subnet is specifically intended to separate public-facing services from internal resources.

  • C. Incorrect.

    Incorrect. Antivirus is an important endpoint security measure, but it does not replace network segmentation. If the web server is compromised, being on the same subnet as employee systems could allow lateral movement or easier access to internal resources. This option reflects the misconception that host-based protections alone are sufficient.

  • D. Incorrect.

    Incorrect. Requiring a VPN for customers to access a public website defeats the purpose of a public-facing web server. A screened subnet is designed to safely publish services to the internet without granting outside users direct access to the internal network.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam