Security+ Lesson

Device Placement And Security Zones for Security+

Last updated: 6/10/2026

Short answer

Secure infrastructure design starts with knowing what needs to communicate and what should not. Device placement is about making a control effective by putting it in the path or location where it can enforce the intended policy. A web application firewall must see web application traffic. A jump server belongs between administrators and sensitive management interfaces. A sensor must be positioned where it can observe the relevant traffic. A remote access gateway must terminate access before users reach internal resources.

Why it appears on the exam

SY0-701 3.2: Apply placement concepts such as security zones, connectivity, attack surface, and device location to secure enterprise infrastructure scenarios.

Key concepts

Concept 1

Required terms

Device placement: deciding where a security device, network device, service, or control should sit in the infrastructure so it can inspect, restrict, route, or protect the right traffic. Security zones: logical or physical areas with similar trust levels, exposure, or control requirements, such as public, DMZ, internal, restricted, management, cloud, or operational technology zones. Attack surface: the set of reachable systems, services, interfaces, ports, paths, and functions that an attacker could target. Connectivity: the allowed communication paths between users, devices, networks, zones, applications, and external services.

Example

A public web server needs Internet access, but the database behind it should not. The web server can sit in a DMZ or public-facing zone while the database remains in an internal restricted zone reachable only from the application path.

Concept 2

How Device Placement And Security Zones works

Secure infrastructure design starts with knowing what needs to communicate and what should not. Device placement is about making a control effective by putting it in the path or location where it can enforce the intended policy. A web application firewall must see web application traffic. A jump server belongs between administrators and sensitive management interfaces. A sensor must be positioned where it can observe the relevant traffic. A remote access gateway must terminate access before users reach internal resources.

Example

Administrators need to manage production servers. A jump server should sit between the administrator network and the management interfaces so direct user-to-server management is not broadly exposed.

Concept 3

Common confusion

Learners often choose a security device based only on its name and ignore placement. The correction is to ask what traffic the device must see or control. Another common confusion is treating a security zone as a product. A zone is a trust boundary or grouping; firewalls, access controls, routing, and monitoring enforce the zone design.

Example

A sensor is deployed on a network segment that never carries payment traffic. It cannot detect payment-segment activity from that location, so the issue is device placement.

Concept 4

What to recognize

Place a control at the correct boundary based on the traffic it must inspect or restrict; Identify which zone should contain public-facing, internal, management, restricted, or third-party-facing resources; Reduce attack surface by removing unnecessary exposure or limiting reachable paths; Determine whether a connectivity path is required, excessive, or missing a control.

Example

A cloud workload allows management from any source IP. The attack surface is larger than necessary; connectivity should be restricted to approved administrative paths.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: A sensor is deployed on a network segment that never carries payment traffic. It cannot detect payment-segment activity from that location, so the issue is device placement. Which answer matches it?

Q2.Read this Security+ situation: Administrators need to manage production servers. A jump server should sit between the administrator network and the management interfaces so direct user-to-server management is not broadly exposed. What is the best match?

Q3.A security team needs to decide what this situation represents: A cloud workload allows management from any source IP. The attack surface is larger than necessary; connectivity should be restricted to approved administrative paths. Which option fits?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8