โ† All CCP Flashcard Decks

Defense-in-Depth Architecture Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Defense-in-Depth Architecture flashcards as text
  1. In a defense-in-depth model, what is the primary purpose of a Security Operations Center (SOC)?

    Answer: Continuously monitor, detect, and respond to threats across all layers

    A SOC provides continuous monitoring and incident response across all security layers, acting as the operational hub of a defense-in-depth strategy.

  2. Which defense-in-depth control specifically addresses the risk of an employee accidentally emailing sensitive data outside the organization?

    Answer: Data loss prevention (DLP)

    DLP solutions monitor and block unauthorized transmission of sensitive data, mitigating accidental or intentional data leakage via email or other channels.

  3. An attacker compromises a low-privileged user account but cannot escalate privileges due to strict role-based access controls. Which defense-in-depth principle does this illustrate?

    Answer: Least privilege and access control layers

    Least privilege limits account permissions so that even a compromised account cannot perform privileged actions, containing the blast radius of the breach.

  4. What is the security advantage of deploying both signature-based and behavior-based detection in an endpoint security solution?

    Answer: It provides complementary detection so known and unknown threats are both covered

    Combining signature-based and behavior-based detection creates defense-in-depth at the endpoint, covering known malware and novel or zero-day attacks.

  5. Which network architecture practice places publicly accessible servers in a separate zone isolated from the internal network?

    Answer: Demilitarized zone (DMZ)

    A DMZ isolates public-facing servers so that if they are compromised, attackers still face internal network controls before reaching sensitive assets.

  6. A company enforces full-disk encryption on all laptops. If a laptop is stolen, which defense-in-depth outcome does this control achieve?

    Answer: Protects data confidentiality even if physical security fails

    Full-disk encryption protects data at the data layer so that theft (a physical control failure) does not result in data exposure to the unauthorized possessor.

  7. Which of the following is a key metric used to evaluate the effectiveness of defense-in-depth controls over time?

    Answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to incidents

    MTTD and MTTR measure how quickly threats are identified and contained, directly reflecting the effectiveness of layered detective and response controls.