nerdexam
GIAC

GSEC · Question #295

Critical information is encrypted within an application accessible only to a small group of administrators, with a separate group of administrators holding the decryption keys. What Defense in Depth…

The correct answer is A. Information-Centric. Encrypting critical data and separating access to data from access to decryption keys is an Information-Centric Defense in Depth strategy that focuses protection on the data asset itself.

Defense in Depth and Protocols

Question

Critical information is encrypted within an application accessible only to a small group of administrators, with a separate group of administrators holding the decryption keys. What Defense in Depth approach is being used?

Options

  • AInformation-Centric
  • BUniform Protection
  • CProtected Enclaves
  • DThreat Vector Analysis

How the community answered

(30 responses)
  • A
    73% (22)
  • B
    7% (2)
  • C
    17% (5)
  • D
    3% (1)

Why each option

Encrypting critical data and separating access to data from access to decryption keys is an Information-Centric Defense in Depth strategy that focuses protection on the data asset itself.

AInformation-CentricCorrect

Information-Centric Defense in Depth centers security controls directly on the data rather than on the network perimeter or host. Encrypting the data and implementing separation of duties for key management ensures that even administrators with application access cannot read the data without coordination with the key-holding group, protecting the information regardless of where it resides.

BUniform Protection

Uniform Protection applies the same level of controls to all assets regardless of their sensitivity, which is the opposite of the targeted, data-focused approach described.

CProtected Enclaves

Protected Enclaves refers to segmenting the network into isolated zones to limit lateral movement, not to encrypting data with separated key management.

DThreat Vector Analysis

Threat Vector Analysis is a process of identifying potential attack paths and is not a Defense in Depth layer or protection model.

Concept tested: Information-Centric Defense in Depth strategy

Source: https://media.defense.gov/2010/Nov/08/2001330307/-1/-1/0/defenseinbreadth.pdf

Topics

#defense in depth#information-centric#data encryption#key management

Community Discussion

No community discussion yet for this question.

Full GSEC Practice