Which statement best describes defense in depth beyond a single control?

Prepare for the NESTOR Session 91 Exam 1 with our comprehensive quiz featuring flashcards and multiple choice questions. Each question is designed with hints and explanations to help deepen your understanding. Ace your exam today!

Multiple Choice

Which statement best describes defense in depth beyond a single control?

Explanation:
Defense in depth means using multiple layers of protection so a breach would have to defeat several independent controls. This approach spreads safeguards across people, processes, and technology, creating redundancy and reducing the risk that any single weakness leads to compromise. Think of combining strong authentication, access control, encryption, regular patching, network segmentation, monitoring, incident response, and security training. If one line of defense is bypassed, others still stand a chance to stop the attacker or limit damage, and ongoing activities like monitoring and rapid response help detect and recover from incidents quickly. Relying on a single strongest control leaves a hole if that control fails or is bypassed. Focusing only on network firewalls misses how users, data, applications, and devices can be attacked, and relying exclusively on user training ignores that people can make mistakes and that technical measures and processes are needed to prevent breaches. So the description that best captures defense in depth is using layered security controls across people, processes, and technology.

Defense in depth means using multiple layers of protection so a breach would have to defeat several independent controls. This approach spreads safeguards across people, processes, and technology, creating redundancy and reducing the risk that any single weakness leads to compromise. Think of combining strong authentication, access control, encryption, regular patching, network segmentation, monitoring, incident response, and security training. If one line of defense is bypassed, others still stand a chance to stop the attacker or limit damage, and ongoing activities like monitoring and rapid response help detect and recover from incidents quickly. Relying on a single strongest control leaves a hole if that control fails or is bypassed. Focusing only on network firewalls misses how users, data, applications, and devices can be attacked, and relying exclusively on user training ignores that people can make mistakes and that technical measures and processes are needed to prevent breaches. So the description that best captures defense in depth is using layered security controls across people, processes, and technology.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy