Question 1 of 30
In a corporate environment, a company is designing its DMZ (Demilitarized Zone) to host a web server, an email server, and a DNS server. The security team is tasked with ensuring that the DMZ is properly segmented from the internal network while allowing necessary traffic to flow. Given the following requirements: the web server must be accessible from the internet, the email server should only accept traffic from the web server, and the DNS server must resolve queries from both the internal network and the internet. Which design principle should the security team prioritize to ensure both functionality and security in this DMZ setup?
Implementing strict access control lists (ACLs) to regulate traffic between the DMZ and internal network.
Utilizing a single firewall to manage all traffic between the DMZ and both the internal network and the internet.
Allowing all traffic from the internal network to the DMZ without restrictions to facilitate ease of access.
Deploying a VPN to connect the DMZ directly to the internal network for secure communications.

Preparing for CISCO 700-760 Cisco Security Architecture for Account Managers? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free