The city needs a public web presence and a protected finance network. Which zoning approach best reduces attack surface?
Select an answer to reveal the explanation.
Short Explanation
Public storefront in the front room, money in the back vault—with a lock between them. DMZ for the web face, internal zone for finance. Flat networks and finance-in-the-DMZ are how attackers get a shorter walk.
Full Explanation
Security zones separate systems by trust level to shrink attack surface. Public-facing web services belong in a DMZ or screened subnet, while sensitive finance systems remain on internal zones with controlled paths between them. Flat networks, placing databases in the DMZ, or removing inter-zone controls increase exposure.