โ† All CCP Flashcard Decks

Defense-in-Depth Architecture Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Defense-in-Depth Architecture flashcards as text
  1. Which defense-in-depth layer is responsible for controlling access to physical hardware, server rooms, and network equipment?

    Answer: Physical security

    Physical security is the outermost defense-in-depth layer protecting hardware and facilities from unauthorized physical access.

  2. A company implements VLAN segmentation, DMZ zones, and internal firewalls. Which defense-in-depth principle does this best represent?

    Answer: Network segmentation and zoning

    Network segmentation and zoning divides the network into isolated areas so a breach in one zone does not immediately compromise others.

  3. In a defense-in-depth model, what is the primary purpose of an intrusion detection system (IDS) deployed inside the network perimeter?

    Answer: Detect threats that bypassed perimeter controls

    An IDS deployed internally acts as a secondary control to detect malicious activity that has already passed through perimeter defenses.

  4. Which concept ensures that no single compromise of a control or layer results in full system access?

    Answer: Layered security (defense-in-depth)

    Defense-in-depth ensures redundant layers so that no single control failure grants total access to protected resources.

  5. A web application firewall (WAF) is best positioned at which defense-in-depth layer?

    Answer: Application layer

    A WAF inspects HTTP/S traffic and filters application-level attacks like SQL injection and XSS, making it an application-layer control.

  6. Which term describes the practice of reducing the number of entry points that an attacker can exploit across all defense layers?

    Answer: Attack surface reduction

    Attack surface reduction minimizes the number of exploitable vectors across all layers, strengthening the overall defense-in-depth posture.

  7. What is the role of endpoint detection and response (EDR) in a defense-in-depth architecture?

    Answer: Monitor and respond to threats on end-user devices

    EDR solutions monitor endpoint activity in real time and provide automated or analyst-driven response to threats at the host layer.