Bastion host
A system deliberately exposed to an untrusted network and hardened to withstand attack, commonly placed in a DMZ to run a public service or act as a controlled point of entry.
A bastion host is a computer placed where an untrusted network, commonly the internet, can reach it, and hardened on the assumption that it will be attacked. Hardening here means running only the services its role needs, removing unnecessary software and accounts, patching promptly, logging in detail and monitoring closely. It commonly sits in a DMZ and performs one exposed function, such as a web or mail relay, an application-level gateway, or an entry point for administrators.
The administrative use has its own name. A jump server is a hardened host through which administrators reach systems in a protected segment, so that management connections come from one monitored place; cloud platforms commonly call this role a bastion. A honeypot is also exposed on purpose, but for the opposite reason: it exists to be attacked and observed, while a bastion host exists to deliver a real service and survive. Because a bastion host is expected to be targeted, what it can reach inside the network is kept as narrow as possible.
Exam relevance: a scenario is likely to describe a single hardened, heavily monitored server facing the internet and ask what it is. Candidates are expected to tell the bastion host (serves and survives) from the honeypot (lures and records) and to link it to minimal services and a DMZ placement.