Which term refers to a network design that uses a screening firewall and a DMZ to expose limited services?

Prepare for the Certified Ethical Hacker Version 11 Exam. Study with comprehensive questions and explanations. Equip yourself with the skills needed for success!

Multiple Choice

Which term refers to a network design that uses a screening firewall and a DMZ to expose limited services?

Explanation:
Screened subnet is the architectural approach where a screening firewall sits at the network edge and a DMZ is placed between two firewalls. The DMZ hosts limited, public-facing services, such as a web or mail server, that need to be reachable from the untrusted network. Traffic from outside first encounters the screening firewall, which filters what can enter the DMZ. Then, another firewall protects the internal network, filtering traffic from the DMZ outward or inward. This creates a safe buffer: services are exposed only as needed, and direct access to internal systems is denied. The DMZ by itself is just a zone, and a firewall is a device, but the screened subnet describes the whole design that uses both to expose limited services securely.

Screened subnet is the architectural approach where a screening firewall sits at the network edge and a DMZ is placed between two firewalls. The DMZ hosts limited, public-facing services, such as a web or mail server, that need to be reachable from the untrusted network. Traffic from outside first encounters the screening firewall, which filters what can enter the DMZ. Then, another firewall protects the internal network, filtering traffic from the DMZ outward or inward. This creates a safe buffer: services are exposed only as needed, and direct access to internal systems is denied. The DMZ by itself is just a zone, and a firewall is a device, but the screened subnet describes the whole design that uses both to expose limited services securely.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy