About this interactive
What you're doing: a transit authority's network is being laid out segment by segment — the untrusted internet, an outer firewall, a DMZ, an inner firewall, the user LAN, the server farm, and a management network — and you place each position in the order traffic crosses it, then defend the two rules that make the layout a design rather than a drawing. Why it matters: segmentation is a decision about where an attacker stops, and the value of a design is measured in what one compromised host can still reach. The DMZ sits between two firewalls because the machine most likely to be owned is the one the public can reach, so owning it should put an attacker in front of a second, differently configured choke point rather than inside the network. The management segment is isolated because the addresses that configure the firewalls must not be reachable from the networks those firewalls exist to contain. How to use it: work the layout out before you read the cards — the ordering positions run outside-in, and the last two positions describe designs that got both rules wrong, so read what is broken before you read the answers.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →