nerdexam
Cisco

300-220 · Question #37

Security countermeasures should:

The correct answer is B. Be layered and comprehensive. Layered and comprehensive security countermeasures - often called defense in depth - are the industry standard because no single control is foolproof; if one layer fails, others remain to detect or contain the threat. A is wrong because relying solely on perimeter defenses…

Threat Hunting Fundamentals

Question

Security countermeasures should:

Options

  • AOnly focus on perimeter defenses
  • BBe layered and comprehensive
  • CRely on security through obscurity
  • DPrioritize aesthetic considerations

How the community answered

(22 responses)
  • B
    91% (20)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Layered and comprehensive security countermeasures - often called defense in depth - are the industry standard because no single control is foolproof; if one layer fails, others remain to detect or contain the threat. A is wrong because relying solely on perimeter defenses (like firewalls) leaves an organization completely exposed once that perimeter is breached - modern attackers routinely bypass it. C is wrong because security through obscurity (hiding how a system works instead of actually securing it) is widely discredited; once the secret is discovered, protection collapses entirely. D is wrong because aesthetics have no bearing on security effectiveness - a beautiful interface with weak controls is still insecure.

Memory tip: Think of it like a medieval castle - walls, a moat, guards, locked doors, and a keep inside. That's layers. One wall alone never protected a kingdom.

Topics

#defense-in-depth#layered-security#security-countermeasures#perimeter-security

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice