Courseiva
easyMultiple Choice

200-201 Practice Question: Protect its internal network from external threats

A company wants to protect its internal network from external threats. Which security principle involves deploying multiple layers of security controls?

⚠ Common exam trap

Cisco often tests the distinction between a broad security strategy (defense in depth) and a specific access control principle (least privilege), so candidates mistakenly choose least privilege when they see 'multiple layers' because they confuse 'layers of permissions' with 'layers of controls.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in depth

Defense in depth (option B) is the correct answer because it describes the strategy of layering independent security controls—such as firewalls, intrusion prevention systems (IPS), endpoint protection, and access controls—so that if one layer fails, another can still block or mitigate an attack. This principle ensures that no single point of failure can compromise the entire network, which is essential for protecting internal assets from external threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege restricts each account to the minimum access required; it does not stack independent controls. It is tempting because it limits blast radius from compromised credentials, and least privilege is correct when the goal is constraining user or service permissions rather than layering defences.

  • ✓

    Defense in depth

    Why this is correct

    Defense in depth satisfies the requirement by layering independent controls—firewalls, segmentation, endpoint protection and identity checks—so no single failure exposes the internal network. Each layer targets a different attack vector, meaning an external threat must defeat several controls in sequence, which directly matches the stem's demand for multiple layers.

  • ✗

    Risk management

    Why it's wrong here

    Risk management identifies, assesses, and treats risk; it does not itself deploy stacked controls. It is tempting because it frames security decisions, and risk management is correct when prioritising which threats to address and selecting treatments, not when describing layered defence.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a single task across people to prevent fraud, so it adds no network-facing controls and cannot filter external traffic. It is tempting because it is a recognised security principle, and it would be correct where one person must not both authorise and execute a sensitive transaction.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.