Defense-in-Depth Architecture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Defense-in-Depth Architecture flashcards as text
Which defense-in-depth layer is primarily addressed by implementing multi-factor authentication (MFA) for user logins?
Answer: Identity and access management layer
MFA strengthens the identity and access management layer by requiring users to prove identity through multiple independent factors.
What is the security benefit of implementing microsegmentation in a data center as part of defense-in-depth?
Answer: It limits lateral movement by isolating individual workloads
Microsegmentation creates granular security zones around individual workloads, preventing attackers from freely moving laterally even after breaching one segment.
A CISO requires that all sensitive data be encrypted both in transit and at rest. Which defense-in-depth principle drives this requirement?
Answer: Ensure confidentiality at the data layer regardless of other control failures
Encrypting data in transit and at rest protects the data layer so that even if network or physical controls fail, the data remains unreadable to unauthorized parties.
Which of the following best describes the 'people' layer in a defense-in-depth model?
Answer: Security awareness training and insider threat programs
The people layer focuses on human controls such as security awareness training, policies, and insider threat programs to reduce human-related risk.
Why is patch management considered an important defense-in-depth control?
Answer: It reduces known vulnerabilities that attackers could exploit at multiple layers
Patch management reduces exploitable vulnerabilities across operating systems, applications, and firmware, strengthening multiple defense layers simultaneously.
A defense-in-depth architecture includes audit logging at the network, host, and application layers. What security function do these logs primarily support?
Answer: Detective and forensic capabilities for incident investigation
Comprehensive audit logs enable security teams to detect anomalies, investigate incidents, and reconstruct attacker actions across multiple layers.
Which scenario best exemplifies the 'fail secure' principle within a defense-in-depth architecture?
Answer: An access control system that denies all access when it fails
Fail secure means a system defaults to a denied/locked state upon failure, ensuring that control failures do not inadvertently grant access.