GSEC · Question #315
An organization keeps its intellectual property in a database. Protection of the data is assigned to one system administrator who marks the data, and monitors for this intellectual property leaving…
The correct answer is C. Information Centric. The information-centric principle of defense-in-depth focuses protection on the data itself - classifying, labeling, and monitoring it - rather than on network perimeters or uniform controls.
Question
An organization keeps its intellectual property in a database. Protection of the data is assigned to one system administrator who marks the data, and monitors for this intellectual property leaving the network. Which defense-In-depth principle does this describe?
Options
- AThreat-Vector Analysis
- BProtected Enclave
- CInformation Centric
- DUniform Protection
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C73% (19)
- D15% (4)
Why each option
The information-centric principle of defense-in-depth focuses protection on the data itself - classifying, labeling, and monitoring it - rather than on network perimeters or uniform controls.
Threat-vector analysis involves identifying and evaluating the paths attackers can use to reach assets, which is not what is described in this scenario.
A protected enclave describes isolating a sensitive segment of the network behind strong perimeter controls, not classifying data and tracking it as it moves.
Information-centric security places the data asset at the center of the protection strategy, meaning controls travel with the data rather than relying solely on boundary defenses. The scenario explicitly describes marking the intellectual property (data classification) and monitoring for it leaving the network (data loss prevention), both hallmarks of information-centric defense. A single administrator owning both the labeling and the monitoring reinforces that the data itself is the protected object.
Uniform protection means applying the same security controls to all data regardless of sensitivity, which is the opposite of singling out specific intellectual property for special monitoring.
Concept tested: Information-centric defense-in-depth principle and data classification
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Topics
Community Discussion
No community discussion yet for this question.