Defense-in-Depth Architecture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Defense-in-Depth Architecture flashcards as text
Which defense-in-depth strategy assumes that internal users and systems may be compromised and enforces strict verification for every access request?
Answer: Zero Trust Architecture
Zero Trust Architecture applies 'never trust, always verify' principles, treating internal traffic with the same scrutiny as external traffic.
An organization uses data classification, DLP tools, and encryption to protect sensitive files. Which defense-in-depth layer is being addressed?
Answer: Data layer
Data layer controls protect information itself through classification, encryption, and loss prevention regardless of the transport path.
A security team deploys honeypots throughout the internal network. What defense-in-depth benefit do honeypots primarily provide?
Answer: Detect lateral movement and gather attacker intelligence
Honeypots lure attackers into fake systems, exposing lateral movement and providing intelligence about attacker tactics without risking real assets.
Which principle ensures that if one security control is defeated, another independent control still protects the asset?
Answer: Redundancy of controls
Redundancy of controls is the core defense-in-depth principle where multiple independent safeguards protect assets even when one fails.
In a layered security architecture, what is the purpose of a bastion host?
Answer: Serve as a hardened gateway for administrative access to internal networks
A bastion host is a specially hardened server that provides a secure and monitored entry point for administrative access, reducing the internal attack surface.
Which control type in defense-in-depth is designed to minimize the impact of a security incident after it has occurred?
Answer: Corrective control
Corrective controls, such as patch management and incident response procedures, reduce the damage after a security event has taken place.
A penetration tester successfully bypasses a perimeter firewall but is blocked by host-based firewalls on each server. Which defense-in-depth outcome does this illustrate?
Answer: Redundant layers prevented the attack from reaching its target
This scenario demonstrates defense-in-depth working as intended — the failure of one layer did not result in full compromise because additional layers were in place.