CISM · Question #248
Which of the following should be implemented to BEST reduce the likelihood of a security breach?
The correct answer is C. A layered security program. A layered security program (defense-in-depth) applies multiple, overlapping controls across people, processes, and technology so that the failure of any single control does not result in a breach. This directly reduces the likelihood of a breach occurring. Data forensics (A)…
Question
Which of the following should be implemented to BEST reduce the likelihood of a security breach?
Options
- AA data forensics program
- BA configuration management program
- CA layered security program
- DAn incident response program
How the community answered
(55 responses)- A5% (3)
- B2% (1)
- C85% (47)
- D7% (4)
Explanation
A layered security program (defense-in-depth) applies multiple, overlapping controls across people, processes, and technology so that the failure of any single control does not result in a breach. This directly reduces the likelihood of a breach occurring. Data forensics (A) and incident response (D) are reactive controls invoked after a breach - they do not reduce likelihood. Configuration management (B) is a single, valuable preventive control, but it addresses only one attack vector. Defense-in-depth covers the broadest range of threats simultaneously.
Topics
Community Discussion
No community discussion yet for this question.