700-270 · Question #38
What are two challenges that are faced by traditional defense-in-depth security solutions? (Choose two.)
The correct answer is B. They require that all components be provided by a single vendor C. Large amounts of logged data lead to poor threat visibility.. Options B and C identify two structural weaknesses baked into traditional defense-in-depth architectures. Why B is correct: Traditional defense-in-depth suites often evolve into tightly coupled, vendor-locked ecosystems. When all components must come from a single vendor, organiz
Question
What are two challenges that are faced by traditional defense-in-depth security solutions? (Choose two.)
Options
- AApplying security policy is generally by manual and static methods
- BThey require that all components be provided by a single vendor
- CLarge amounts of logged data lead to poor threat visibility.
- DThey mandate network change control
- ESecurity services must be outsourced.
How the community answered
(37 responses)- A3% (1)
- B86% (32)
- D8% (3)
- E3% (1)
Explanation
Options B and C identify two structural weaknesses baked into traditional defense-in-depth architectures.
Why B is correct: Traditional defense-in-depth suites often evolve into tightly coupled, vendor-locked ecosystems. When all components must come from a single vendor, organizations lose flexibility - they can't easily adopt best-in-class tools, and a gap in that vendor's portfolio becomes a gap in the entire security posture.
Why C is correct: Layering many independent security controls (firewalls, IDS, AV, DLP, etc.) generates enormous volumes of log data from disconnected sources. Without unified correlation, defenders are buried in noise - more data actually reduces actionable threat visibility rather than improving it.
Why the distractors are wrong: A (manual/static policy) describes a real IT problem but is not the defining challenge specific to defense-in-depth architecture as an approach. D (mandating change control) is a general network governance process, not a defense-in-depth limitation. E (outsourcing) has no inherent relationship to whether a security design uses layered defenses.
Memory tip: Think "B-C = Bound to one vendor, Can't see the threats" - vendor lock-in limits your tool choices, and log overload blinds your analysts despite having lots of data.
Topics
Community Discussion
No community discussion yet for this question.