For the third interface, or one of the interface, you can configure not to forward traffic to one of the other interface.
Example:
1) Inside interface can forward to DMZ and Outside
2) Outside interface can forward to Inside and DMZ
3) DMZ can only forward to one of the other interface, ie: either inside or outside (typically, with Base license, people configure DMZ not to be able to forward to the inside zone, and have access to the Outside).