nerdexam
Cisco

700-270 · Question #38

What are two challenges that are faced by traditional defense-in-depth security solutions? (Choose two.)

The correct answer is B. They require that all components be provided by a single vendor C. Large amounts of logged data lead to poor threat visibility.. Options B and C identify two structural weaknesses baked into traditional defense-in-depth architectures. Why B is correct: Traditional defense-in-depth suites often evolve into tightly coupled, vendor-locked ecosystems. When all components must come from a single vendor, organiz

Identifying Customer Business Challenges and Opportunities

Question

What are two challenges that are faced by traditional defense-in-depth security solutions? (Choose two.)

Options

  • AApplying security policy is generally by manual and static methods
  • BThey require that all components be provided by a single vendor
  • CLarge amounts of logged data lead to poor threat visibility.
  • DThey mandate network change control
  • ESecurity services must be outsourced.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    86% (32)
  • D
    8% (3)
  • E
    3% (1)

Explanation

Options B and C identify two structural weaknesses baked into traditional defense-in-depth architectures.

Why B is correct: Traditional defense-in-depth suites often evolve into tightly coupled, vendor-locked ecosystems. When all components must come from a single vendor, organizations lose flexibility - they can't easily adopt best-in-class tools, and a gap in that vendor's portfolio becomes a gap in the entire security posture.

Why C is correct: Layering many independent security controls (firewalls, IDS, AV, DLP, etc.) generates enormous volumes of log data from disconnected sources. Without unified correlation, defenders are buried in noise - more data actually reduces actionable threat visibility rather than improving it.

Why the distractors are wrong: A (manual/static policy) describes a real IT problem but is not the defining challenge specific to defense-in-depth architecture as an approach. D (mandating change control) is a general network governance process, not a defense-in-depth limitation. E (outsourcing) has no inherent relationship to whether a security design uses layered defenses.

Memory tip: Think "B-C = Bound to one vendor, Can't see the threats" - vendor lock-in limits your tool choices, and log overload blinds your analysts despite having lots of data.

Topics

#Defense-in-depth limitations#Vendor lock-in#Security logging and visibility#Traditional security architecture

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice