What is the concept of 'defense in depth'?
- A.Using the strongest single security measure available
- B.Implementing multiple layers of security controls so that if one fails, others still protect the system
- C.Placing all security equipment in one central location, since defence in depth removes any need for monitoring at the perimeter
- D.Defending only the network perimeter
Why B is correct
Defense in depth (also called layered security) uses multiple overlapping security controls at different levels (network, host, application, data). If an attacker bypasses one layer (e.g., the firewall), additional layers (e.g., intrusion detection, endpoint protection, access controls) still provide protection.
Know someone studying for Security Fundamentals? Send them this one.