Demilitarized zone (DMZ, screened subnet)
A network segment between an untrusted network and the internal one that holds the systems outsiders must reach, with traffic into the internal network limited to permitted flows.
A demilitarized zone is a network segment placed between an untrusted network, usually the internet, and the internal network. It holds the systems that outside users have to reach, such as public web servers, mail relays and external DNS servers. Study sources commonly use the term screened subnet for the same idea. It is commonly built either with one firewall that has a separate interface for the DMZ or with two firewalls, one on each side of it.
The point of the design is containment. Systems in the DMZ face the internet and are more likely to be compromised than internal systems, so traffic from the DMZ into the internal network is restricted to specific permitted flows, such as a web server reaching one database, rather than open access. The DMZ hosts are hardened for the same reason, in the manner of a bastion host. A common mistake is to treat a DMZ server as trusted because the organisation owns it. The DMZ is an application of network segmentation.
Exam relevance: a scenario is likely to ask where a public-facing server belongs, or what should happen to traffic from the DMZ into the internal network. Candidates are expected to place internet-facing services in the DMZ and to allow only narrowly defined flows inward from it.