SY0-701 General Security Concepts Practice Question
A company uses MFA, endpoint protection, firewalls, and network segmentation together to protect a customer portal. Which security principle does this best illustrate?
⚠ Common exam trap
Watch out — candidates often confuse 'defense in depth' with 'zero trust' because both involve multiple controls, but zero trust specifically requires continuous verification and least-privilege access for every request, whereas defense in depth is simply the layering of independent controls without necessarily requiring per-request verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth, because multiple layers protect the same asset.
Defense in depth is the correct principle because the company is deploying multiple, overlapping security controls—MFA, endpoint protection, firewalls, and network segmentation—to protect the same customer portal. This layered approach ensures that if one control fails (e.g., a firewall rule is misconfigured), other controls (e.g., endpoint detection or segmentation) still provide protection, reducing the overall risk of a single point of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Need-to-know, because users only see the data assigned to them.
Why it's wrong here
Need-to-know is an access control principle that limits data visibility to individuals who require it for their job functions. The scenario describes MFA, endpoint protection, firewalls, and segmentation—controls that form multiple protective layers around assets. It is not about restricting which data a user sees, but about stacking safeguards against different types of threats. Thus, while need-to-know is a valid security practice, it does not explain the layered architecture described.
- ✗
Separation of duties, because no single person performs every security task.
Why it's wrong here
Separation of duties is an administrative control that splits critical tasks among different people to prevent fraud or errors, such as one person approving a purchase and another authorizing payment. The question depicts technical controls—MFA, endpoint protection, firewalls, and segmentation—that operate together to protect the same asset, not a division of responsibilities among personnel. There is no indication that task decomposition among individuals is relevant. The correct concept is about multiple technical layers, not organizational role assignments.
- ✓
Defense in depth, because multiple layers protect the same asset.
Why this is correct
Defense in depth is the correct principle because it employs multiple independent layers of security so that if one control fails, another continues to protect the asset. MFA verifies identity, endpoint protection blocks malicious software, firewalls filter network traffic, and segmentation limits lateral movement—each addresses a different attack vector. This redundancy and diversity of controls means a single vulnerability or bypass does not compromise the entire system. The scenario explicitly lists these layered safeguards working together to reduce overall risk.
- ✗
Zero trust, because the portal is hosted in the cloud.
Why it's wrong here
Zero trust is a security model that assumes no entity is trusted by default, requiring continuous verification of every request, device, and user regardless of location. Hosting a portal in the cloud does not automatically implement zero trust; the cloud is just an infrastructure location. The scenario does not mention continuous authentication, micro-segmentation, least-privilege access, or other zero-trust components. Therefore, the cloud hosting detail is irrelevant to identifying zero trust and does not explain the layered protections described.
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.