Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.
Start practicing
Defense in Depth — choose a session length
Free · No account required
Domain overview
Defense in Depth on GSEC covers layering preventive, detective, and corrective controls across hosts, networks, applications, and data. Questions present realistic scenarios—offsite tape handling, perimeter firewalls with VLAN segmentation, EHR architectures, Linux build pipelines—and ask you to select controls that reduce impact when one layer fails, including encryption, least privilege, and monitoring.
Exam objectives
Applying full-disk or tape encryption (LUKS, BitLocker) so lost media cannot expose data
Using host-based firewalls, iptables/nftables, and VLAN segmentation to limit lateral movement
Deploying EDR, SIEM, and file integrity monitoring (AIDE, Tripwire) for detection layers
Hardening build servers with least privilege, sudo restrictions, SELinux/AppArmor, and network isolation
Treating defense in depth as simply buying more tools rather than ensuring independent layers that each address a distinct failure mode.
Assuming encryption alone protects data in use or that network segmentation replaces endpoint controls; candidates pick one control when the scenario needs layered answers.
Confusing detective controls (logging, IDS, EDR alerts) with preventive controls (firewalls, ACLs, encryption) when the question asks for a specific control category.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?
2Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?
3Which of the following represents an example of applying defense in depth at the host level?
4When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?
5Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?
6Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?
7Why does the inclusion of detective controls improve a defense in depth strategy?
8A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. During a purple-team exercise, analysts discover that a contractor's laptop, once connected to the internal network, can reach the HR payroll server directly over SMB. The security team wants to enforce the principle of least privilege on this internal traffic. Which control should they implement to best achieve this?
9A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?
10A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?
11A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?
12A small financial firm has a flat network with no internal segmentation. The security team wants to apply defense in depth to limit the blast radius of a compromised workstation. Which action best aligns with that goal?
13A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?
14A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)
15A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)
16A government agency uses a defense in depth architecture with strict perimeter firewalls, network segmentation, and endpoint protection. During a red team exercise, attackers gained initial access via a phishing email and then moved laterally by exploiting a misconfigured internal server. The agency wants to improve its ability to detect and respond to such lateral movement. Which control would be most effective to add?
17A retail company's e-commerce site is being targeted by credential stuffing attacks. The security team wants to add a control that slows automated login attempts while preserving a smooth experience for legitimate customers. Which control best fits this requirement?
18A software development company wants to protect its source code repositories from insider threats and external attackers. The company already uses network segmentation and endpoint detection. The security team proposes adding a control that requires two distinct factors before developers can access repositories, even from within the corporate network. Which control best meets this requirement?
19A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?
20A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?
Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.
The Courseiva GSEC question bank contains 20 questions in the Defense in Depth domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Defense in Depth domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included