[SOLVED] Conceptual: Order of Devices (DMZ/Web Server)

Terpinator

Reputable
Apr 12, 2017
84
2
4,565
Hello everyone,

I have recently begun studying for Security+ and have seem to hit what looks to be a contradictory part, unless my understanding of the concept is incorrect. The question presented is below:

"For traffic coming from the Internet into the network, which of the following is the correct order in which devices should receive the traffic?"

The answer presented is below:

" Firewall -> DMZ -> Firewall -> SSL accelerator -> Load balancer -> Web Server

It would seem to me that the topology of this network would be a back to back model. My confusion is stemming from the fact that I thought that the web server should be within the DMZ itself and NOT within the internal network. Looking at the traffic path in the answer, it passes both firewalls before finally hitting the web server which to me says the web server is not within the DMZ.
 

Terpinator

Reputable
Apr 12, 2017
84
2
4,565
That IS within the DMZ.
The other internal LAN is a whole other swim lane and chain of devices.

Ah I see. It looks like my confusion may be coming from how they were shown. The explanation in the book made seem like the following:

Internal network -> Firewall -> DMZ -> Firewall -> Internet

With that in mind, traversing two firewalls made me mentally place the server within the internal network. So I ended up immediately discarding the correct answer. I guess the wording between the explanation and question confused me.
 

USAFRet

Titan
Moderator
Ah I see. It looks like my confusion may be coming from how they were shown. The explanation in the book made seem like the following:

Internal network -> Firewall -> DMZ -> Firewall -> Internet

With that in mind, traversing two firewalls made me mentally place the server within the internal network. So I ended up immediately discarding the correct answer. I guess the wording between the explanation and question confused me.
Firewall 1 is to prevent stuff from reaching the DMZ.
Firewall 2 is to get what the DMZ and Firewall 1 don't catch.

And yes, sometimes Sec+ questions are...weird.