nerdexam
GIAC

GSEC · Question #3

Your organization is developing a network protection plan. No single aspect of your network seems more important than any other. You decide to avoid separating your network into segments or categorizi

The correct answer is A. Uniform protection. Applying identical security controls to every device with no network segmentation or asset categorization is called uniform protection.

Penetration Testing Foundations & Reconnaissance

Question

Your organization is developing a network protection plan. No single aspect of your network seems more important than any other. You decide to avoid separating your network into segments or categorizing the systems on the network. Each device on the network is essentially protected in the same manner as all other devices. This style of defense-in-depth protection is best described as which of the following?

Options

  • AUniform protection
  • BThreat-oriented
  • CInformation-centric
  • DProtected enclaves

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    6% (2)
  • C
    17% (6)
  • D
    3% (1)

Why each option

Applying identical security controls to every device with no network segmentation or asset categorization is called uniform protection.

AUniform protectionCorrect

Uniform protection is a defense-in-depth strategy where every device and network zone receives the same type and level of security control, with no differentiation based on asset criticality or data sensitivity. This approach is appropriate when no single part of the network is considered more important than another, and it simplifies policy management by avoiding tiered or segmented security architectures.

BThreat-oriented

Threat-oriented protection tailors security controls around specific known attack vectors or threat actor profiles rather than applying identical protection uniformly to all assets.

CInformation-centric

Information-centric protection directs the strongest controls toward specific high-value data rather than treating all devices and segments equally.

DProtected enclaves

Protected enclaves involves dividing the network into separately secured and isolated segments, which directly contradicts the described approach of avoiding segmentation.

Concept tested: Defense-in-depth uniform protection strategy

Source: https://csrc.nist.gov/publications/detail/sp/800-27/rev-a/final

Topics

#uniform protection#defense-in-depth#network design#security architecture

Community Discussion

No community discussion yet for this question.

Full GSEC Practice