N10-009 exam dumps

N10-009 practice question 281 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 281

Single answerZones: Trusted vs. untrusted, Screened subnet

A company hosts its public web server and external DNS server on a separate network segment between the internet-facing firewall and the internal LAN. The security team wants internet users to reach those public services, but they do not want external users to have direct access to the internal finance and HR systems. Which network design best meets this requirement?

  1. A

    Place the web and DNS servers in a screened subnet (DMZ), treat the internet as untrusted, and allow only required traffic from the untrusted zone to those public servers

  2. B

    Place the web and DNS servers on the trusted internal LAN so internal security tools can monitor them more easily

  3. C

    Connect the web and DNS servers directly to the internet without firewall filtering so public users can reach them with fewer hops

  4. D

    Put the finance and HR systems in the screened subnet and leave the web and DNS servers on the internal LAN

Show answer and explanation

Correct answer: A

Explanation

The best practice is to place publicly accessible systems in a screened subnet (DMZ) and keep sensitive business systems on the trusted internal network. The internet is considered an untrusted zone because external traffic cannot be assumed safe. Firewalls should enforce tightly scoped rules so only required traffic from the untrusted zone reaches the DMZ, and access from the DMZ to the trusted network should be heavily restricted. This layered approach aligns with common enterprise security architecture guidance and network segmentation best practices, including principles reflected in firewall and DMZ design recommendations from vendors and security frameworks such as NIST network boundary protection guidance.

  • A. Correct.

    Correct. A screened subnet, commonly called a DMZ, is specifically designed to host public-facing services such as web and DNS servers while separating them from the trusted internal network. In this design, the internet is treated as an untrusted zone, and firewall rules permit only the necessary inbound traffic, such as HTTP/HTTPS and DNS, to the servers in the screened subnet. This reduces the risk that a compromise of a public server will provide direct access to sensitive internal systems.

  • B. Incorrect.

    Incorrect. Putting public-facing servers on the trusted internal LAN increases risk because those systems are exposed to untrusted internet traffic. Even if internal monitoring tools are present, this placement breaks the security principle of network segmentation and can allow an attacker who compromises a public server to move more easily toward sensitive internal resources.

  • C. Incorrect.

    Incorrect. Directly connecting public servers to the internet without firewall filtering removes an important security control. Firewalls are used to enforce access policies between untrusted and protected zones. Fewer hops does not outweigh the loss of inspection, filtering, logging, and segmentation.

  • D. Incorrect.

    Incorrect. Finance and HR systems contain sensitive internal data and belong in the trusted zone, not in a screened subnet. A screened subnet is intended for systems that must be reachable from untrusted networks. Moving sensitive internal systems there would expose them unnecessarily, while leaving public servers on the internal LAN defeats the purpose of the screened subnet.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam