What is the concept of defense in depth?
- A.Only encrypting the most sensitive data
- B.Placing all security devices at the network perimeter; defence in depth removes any need for monitoring at the perimeter
- C.Using a single very strong security control, and defence in depth is satisfied by a single well configured firewall
- D.Implementing multiple layers of security controls so that if one fails, others still provide protection
Why D is correct
Defense in depth uses multiple, overlapping security layers (firewalls, IDS, access controls, encryption, training, physical security) so that compromise of one layer doesn't result in a complete breach. Like a castle with walls, moats, and guards, each layer provides additional protection.
Know someone studying for Security Fundamentals? Send them this one.