Question 1 of 30
In a corporate environment, a security architect is tasked with designing a network that effectively separates sensitive data from less secure areas. The architect decides to implement a multi-zone architecture, which includes a DMZ (Demilitarized Zone), an internal network zone, and an external zone. Given the following requirements: 1) The DMZ must host public-facing services while limiting direct access to the internal network, 2) The internal network must be protected from external threats, and 3) The external zone should allow for minimal access to the DMZ for monitoring purposes. Which of the following configurations best illustrates the principles of security domains and zones in this scenario?
The DMZ is configured with a firewall that allows only HTTP and HTTPS traffic from the external zone, while the internal network is protected by a separate firewall that blocks all incoming traffic from the external zone and only allows specific outbound traffic to the DMZ for monitoring.
The DMZ is connected directly to the internal network without any firewall, allowing all traffic between the two zones, while the external zone has unrestricted access to the DMZ.
The internal network is exposed to the external zone through a single firewall that allows all types of traffic, while the DMZ has no restrictions on incoming traffic from the external zone.
The external zone is configured to allow all traffic to the DMZ, which in turn has unrestricted access to the internal network, creating a flat network structure without any segmentation.

Preparing for CISCO 700-765 Cisco Security Architecture for System Engineers? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free