TechKnowSurge
CompTIA Security+ 3.1 CompTIA Network+ 4.1 CompTIA Security+ 3.2 CompTIA Network+ 4.3 CompTIA Network+ 1.6 Cisco CCST Cybersecurity 2.3
InteractiveSecurityFree

Security Zone Designer

Lay out a segmented network segment by segment — internet, DMZ, internal LAN, server farm, management — then defend the two rules that make the layout a design rather than a drawing.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: a transit authority's network is being laid out segment by segment — the untrusted internet, an outer firewall, a DMZ, an inner firewall, the user LAN, the server farm, and a management network — and you place each position in the order traffic crosses it, then defend the two rules that make the layout a design rather than a drawing. Why it matters: segmentation is a decision about where an attacker stops, and the value of a design is measured in what one compromised host can still reach. The DMZ sits between two firewalls because the machine most likely to be owned is the one the public can reach, so owning it should put an attacker in front of a second, differently configured choke point rather than inside the network. The management segment is isolated because the addresses that configure the firewalls must not be reachable from the networks those firewalls exist to contain. How to use it: work the layout out before you read the cards — the ordering positions run outside-in, and the last two positions describe designs that got both rules wrong, so read what is broken before you read the answers.

What you'll learn

Aligned to

CompTIA Security+
3.1 Compare and contrast security implications of different architecture models.
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
CompTIA Network+
4.1 Explain the importance of basic network security concepts.
4.3 Given a scenario, apply network security features, defense techniques, and solutions.
1.6 Compare and contrast network topologies, architectures, and types.
Cisco CCST Cybersecurity
2.3 Describe network infrastructure and technologies

Key terms

Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Screened Subnet
A dedicated network segment that hosts publicly accessible services, isolating them from the internal network so that a compromised host cannot directly access internal resources.
Demilitarized Zone
DMZ
A network segment that sits between a trusted internal network and an untrusted external network, hosting public-facing services.
Out-of-Band Management
A method of managing network devices using a physically separate network or connection, independent of the primary data network.
Trust Boundary
A point within a system or network where the level of trust or security changes, separating more trusted zones from less trusted ones.
Network Isolation
The practice of separating a network segment so it has no direct connectivity to other networks or the internet, preventing unauthorized access to sensitive resources.
Jump Server
A hardened intermediary host used to provide controlled access to devices within a separate network segment, also known as a jump box or jump host.
Bastion Host
A hardened server placed on the network perimeter that serves as a gateway to protect internal servers from external threats.
Management VLAN
A VLAN reserved for administrative access to network devices, separating switch and router management traffic from user data traffic so that a compromised end device does not share a broadcast domain with the management addresses.
Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Lateral Movement
A MITRE ATT&CK tactic in which an adversary pivots from one compromised system to other systems within the same network environment.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.

Topics

Interactive Build

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →