Defense-in-Depth Architecture Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Defense-in-Depth Architecture flashcards as text
Which defense-in-depth layer is responsible for controlling access to physical hardware, server rooms, and network equipment?
Answer: Physical security
Physical security is the outermost defense-in-depth layer protecting hardware and facilities from unauthorized physical access.
A company implements VLAN segmentation, DMZ zones, and internal firewalls. Which defense-in-depth principle does this best represent?
Answer: Network segmentation and zoning
Network segmentation and zoning divides the network into isolated areas so a breach in one zone does not immediately compromise others.
In a defense-in-depth model, what is the primary purpose of an intrusion detection system (IDS) deployed inside the network perimeter?
Answer: Detect threats that bypassed perimeter controls
An IDS deployed internally acts as a secondary control to detect malicious activity that has already passed through perimeter defenses.
Which concept ensures that no single compromise of a control or layer results in full system access?
Answer: Layered security (defense-in-depth)
Defense-in-depth ensures redundant layers so that no single control failure grants total access to protected resources.
A web application firewall (WAF) is best positioned at which defense-in-depth layer?
Answer: Application layer
A WAF inspects HTTP/S traffic and filters application-level attacks like SQL injection and XSS, making it an application-layer control.
Which term describes the practice of reducing the number of entry points that an attacker can exploit across all defense layers?
Answer: Attack surface reduction
Attack surface reduction minimizes the number of exploitable vectors across all layers, strengthening the overall defense-in-depth posture.
What is the role of endpoint detection and response (EDR) in a defense-in-depth architecture?
Answer: Monitor and respond to threats on end-user devices
EDR solutions monitor endpoint activity in real time and provide automated or analyst-driven response to threats at the host layer.