nerdexam
Isaca

CISM · Question #248

Which of the following should be implemented to BEST reduce the likelihood of a security breach?

The correct answer is C. A layered security program. A layered security program (defense-in-depth) applies multiple, overlapping controls across people, processes, and technology so that the failure of any single control does not result in a breach. This directly reduces the likelihood of a breach occurring. Data forensics (A)…

Submitted by jakub_pl· Apr 18, 2026Information Security Risk Management

Question

Which of the following should be implemented to BEST reduce the likelihood of a security breach?

Options

  • AA data forensics program
  • BA configuration management program
  • CA layered security program
  • DAn incident response program

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    85% (47)
  • D
    7% (4)

Explanation

A layered security program (defense-in-depth) applies multiple, overlapping controls across people, processes, and technology so that the failure of any single control does not result in a breach. This directly reduces the likelihood of a breach occurring. Data forensics (A) and incident response (D) are reactive controls invoked after a breach - they do not reduce likelihood. Configuration management (B) is a single, valuable preventive control, but it addresses only one attack vector. Defense-in-depth covers the broadest range of threats simultaneously.

Topics

#Security Architecture#Risk Mitigation#Defense in Depth#Preventive Controls

Community Discussion

No community discussion yet for this question.

Full CISM Practice