CCSP · Question #280
In attempting to provide a layered defense, the security practitioner should convince senior management to include security controls of which type? Response:
The correct answer is D. All of the above. A robust layered defense strategy requires a combination of all types of security controls to protect assets comprehensively.
Question
In attempting to provide a layered defense, the security practitioner should convince senior management to include security controls of which type? Response:
Options
- ATechnological
- BPhysical
- CAdministrative
- DAll of the above
How the community answered
(33 responses)- A3% (1)
- C6% (2)
- D91% (30)
Why each option
A robust layered defense strategy requires a combination of all types of security controls to protect assets comprehensively.
Technological controls alone, while crucial, do not cover physical access or human behavior aspects of security.
Physical controls prevent unauthorized access to facilities and hardware but do not protect against cyber threats or user errors.
Administrative controls establish policies and procedures but require technological and physical enforcement to be fully effective.
A layered defense, also known as defense in depth, mandates the implementation of security controls from all categories: Technological (e.g., firewalls, encryption), Physical (e.g., locks, fences), and Administrative (e.g., policies, training) to provide multiple barriers against threats. Relying on only one type of control leaves significant gaps in an organization's security posture.
Concept tested: Defense in depth security controls
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-overview
Topics
Community Discussion
No community discussion yet for this question.