Which statement about DMZ (Screened Subnet) is true?

Study for the EC-Council Certified Security Specialist (ECSS) Test. Enhance your skills with flashcards and multiple-choice questions; each question provides hints and explanations. Prepare confidently for your exam!

Multiple Choice

Which statement about DMZ (Screened Subnet) is true?

Explanation:
A DMZ is a screened subnet designed to host services that must be reachable from the internet while keeping the internal network protected. The statement that it contains hosts that offer public services is correct because the DMZ is specifically set up to expose public-facing servers—such as web, mail, or DNS servers—to external users. These servers are isolated from the internal LAN so that any compromise or intrusion attempt via the public services doesn’t directly threaten internal resources. This design isn’t about internal-only servers, nor is the DMZ the main LAN. Its purpose is to provide a controlled, limited surface for public access while maintaining a barrier to the private network.

A DMZ is a screened subnet designed to host services that must be reachable from the internet while keeping the internal network protected. The statement that it contains hosts that offer public services is correct because the DMZ is specifically set up to expose public-facing servers—such as web, mail, or DNS servers—to external users. These servers are isolated from the internal LAN so that any compromise or intrusion attempt via the public services doesn’t directly threaten internal resources.

This design isn’t about internal-only servers, nor is the DMZ the main LAN. Its purpose is to provide a controlled, limited surface for public access while maintaining a barrier to the private network.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy