What is the concept of defense in depth?
- A.A. Using a single very strong security control
- B.C. Placing all security devices at the network perimeter
- C.B. Implementing multiple layers of security controls so that if one fails, others still provide protection
- D.D. Only encrypting the most sensitive data
Why C is correct
Defense in depth uses multiple, overlapping security layers (firewalls, IDS, access controls, encryption, training, physical security) so that compromise of one layer doesn't result in a complete breach. Like a castle with walls, moats, and guards, each layer provides additional protection.
Know someone studying for Security Fundamentals? Send them this one.