nerdexam
(ISC)2

CCSP · Question #280

In attempting to provide a layered defense, the security practitioner should convince senior management to include security controls of which type? Response:

The correct answer is D. All of the above. A robust layered defense strategy requires a combination of all types of security controls to protect assets comprehensively.

Submitted by jakub_pl· Apr 18, 2026Cloud Concepts, Architecture and Design

Question

In attempting to provide a layered defense, the security practitioner should convince senior management to include security controls of which type? Response:

Options

  • ATechnological
  • BPhysical
  • CAdministrative
  • DAll of the above

How the community answered

(33 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    91% (30)

Why each option

A robust layered defense strategy requires a combination of all types of security controls to protect assets comprehensively.

ATechnological

Technological controls alone, while crucial, do not cover physical access or human behavior aspects of security.

BPhysical

Physical controls prevent unauthorized access to facilities and hardware but do not protect against cyber threats or user errors.

CAdministrative

Administrative controls establish policies and procedures but require technological and physical enforcement to be fully effective.

DAll of the aboveCorrect

A layered defense, also known as defense in depth, mandates the implementation of security controls from all categories: Technological (e.g., firewalls, encryption), Physical (e.g., locks, fences), and Administrative (e.g., policies, training) to provide multiple barriers against threats. Relying on only one type of control leaves significant gaps in an organization's security posture.

Concept tested: Defense in depth security controls

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-overview

Topics

#Layered Defense#Defense in Depth#Security Controls#Types of Security Controls

Community Discussion

No community discussion yet for this question.

Full CCSP Practice