1C0X2 Apprentice Course Block III Practice Test

Access More Questions
In a network diagram, where would you place a firewall to segment a trusted network from an untrusted network?
Correct Answer:
At the network perimeter, between the internal LAN and the Internet or DMZ.
Explanation:
You enforce the boundary between trusted and untrusted networks by placing a firewall at the network perimeter, between the internal LAN and the Internet or DMZ. This position creates a single choke point where traffic can be inspected and filtered according to security rules before it crosses into or out of the trusted network. It lets you control what enters from untrusted networks and what leaves the internal network, helps protect internal hosts, and supports exposing only necessary services through a DMZ. Choosing a host-based firewall on individual machines only protects each device, not the whole network boundary. Putting a firewall on the internal switch wouldn’t create a boundary to enforce policy between trusted and untrusted sites. Adding firewalls between every pair of servers is unnecessary and impractical. The perimeter placement provides a scalable, centralized means to enforce access control at the critical boundary.

Access more questions from this quiz

Continue to 1C0X2 Apprentice Course Block III Practice Test for more practice questions and the full quiz experience.

Access More Questions