nerdexam
Isaca

CISM · Question #890

The MOST important attribute to be considered in designing defense-in-depth controls is that:

The correct answer is A. failure of one layer does not cause the next layer to fail. The entire premise of defense-in-depth is layered, independent controls where no single layer is a single point of failure. If one layer fails, the next must remain fully functional and unaffected. This independence is what gives the strategy its resilience. A strong single…

Submitted by yuki_2020· Apr 18, 2026Information Security Program Development and Management

Question

The MOST important attribute to be considered in designing defense-in-depth controls is that:

Options

  • Afailure of one layer does not cause the next layer to fail.
  • Bthe strongest control can substitute multiple layers of controls.
  • Cthe cost of control at each layer contributes to the overall cost of protection.
  • Da consistent approach is used for each layer.

How the community answered

(29 responses)
  • A
    90% (26)
  • C
    3% (1)
  • D
    7% (2)

Explanation

The entire premise of defense-in-depth is layered, independent controls where no single layer is a single point of failure. If one layer fails, the next must remain fully functional and unaffected. This independence is what gives the strategy its resilience. A strong single control (B) violates the layering principle. Cost contribution (C) is a consideration but not the defining attribute. Consistency (D) is a design guideline, not the core requirement. The critical attribute is that each layer operates independently so that one compromise does not cascade to the next.

Topics

#Defense-in-depth#Layered security#Security control design#Security architecture

Community Discussion

No community discussion yet for this question.

Full CISM Practice