Courseiva
General Security ConceptsmediumMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

A security architect is designing a defense strategy for a database containing sensitive customer records. The architect implements a network firewall to restrict inbound traffic to only the application server, enforces file-level encryption for the database files, requires multi-factor authentication for all administrative access, and deploys a database activity monitoring system to alert on unusual queries. Which security principle is the architect primarily applying?

⚠ Common exam trap

A common mix-up: candidates confuse defense in depth with least privilege because both involve multiple controls, but defense in depth is about layering different types of controls, not just restricting permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Defense in depth

The architect is applying defense in depth by layering multiple independent security controls: a network firewall, file-level encryption, multi-factor authentication, and database activity monitoring. This strategy ensures that if one control fails, others still provide protection, which is the core principle of defense in depth. Each layer addresses a different attack vector, making it significantly harder for an attacker to compromise the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Least privilege

    Why it's wrong here

    The scenario does not describe minimizing user permissions; it focuses on layering different types of controls. Least privilege is about granting only the minimum necessary access rights, which is not the primary principle demonstrated here.

    When this WOULD be correct

    A scenario where a security architect restricts database user permissions to only the specific tables and queries needed for their job role, and implements role-based access control to ensure no user has more access than required. The question would emphasize minimizing access rights rather than layering controls.

  • Defense in depth

    Why this is correct

    Defense in depth is a security architecture principle that deliberately deploys multiple, independent layers of controls—such as firewalls, intrusion detection systems, full-disk encryption, and multi-factor authentication—so that a failure or bypass of any single layer does not leave the system exposed. The architect's strategy of combining preventive, detective, and corrective technical controls across different points in the attack surface is the exact embodiment of this layered-defense model, where residual risk from one control is mitigated by another.

  • Separation of duties

    Why it's wrong here

    Separation of duties is an administrative control that splits critical tasks or privileges among multiple individuals to prevent conflicts of interest, fraud, or accidental damage—for example, requiring two different people to approve and execute a wire transfer. The scenario describes only technical security controls (e.g., firewalls, MFA, monitoring) and says nothing about dividing human responsibilities or restricting access per role. Thus, this principle is not demonstrated by the architect's strategy, which is focused on in-depth technical layering rather than on organizational task distribution.

    When this WOULD be correct

    A question where an organization splits database administration and security auditing roles between two different teams, or requires two people to approve changes to sensitive data, would make separation of duties the correct answer.

  • Fail safe

    Why it's wrong here

    Fail safe refers to a system defaulting to a secure state when a failure occurs (e.g., a door locking on power loss). The architect's approach does not specifically address failure modes but instead builds layered defenses.

    When this WOULD be correct

    A scenario where a security control is designed to default to a secure state upon failure, such as a door lock that remains locked during a power outage, or a firewall that blocks all traffic if it crashes, would make fail safe the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Defense in depthCorrect answer

Why this is correct

Defense in depth is a security architecture principle that deliberately deploys multiple, independent layers of controls—such as firewalls, intrusion detection systems, full-disk encryption, and multi-factor authentication—so that a failure or bypass of any single layer does not leave the system exposed. The architect's strategy of combining preventive, detective, and corrective technical controls across different points in the attack surface is the exact embodiment of this layered-defense model, where residual risk from one control is mitigated by another.

Least privilegeWrong answer — click to see why

Why this is wrong here

The question describes multiple overlapping controls (firewall, encryption, MFA, monitoring) that together provide layered security, which is the essence of defense in depth, not least privilege. Least privilege would focus on restricting permissions to the minimum necessary, which is not the primary theme here.

★ When this WOULD be the correct answer

A scenario where a security architect restricts database user permissions to only the specific tables and queries needed for their job role, and implements role-based access control to ensure no user has more access than required. The question would emphasize minimizing access rights rather than layering controls.

Why candidates choose this

Candidates may confuse the concept of least privilege with the idea of restricting inbound traffic to only the application server, which is a form of access restriction, but the question's broader focus on multiple layers makes defense in depth the correct answer.

Separation of dutiesWrong answer — click to see why

Why this is wrong here

The scenario describes multiple overlapping security controls (firewall, encryption, MFA, monitoring), which is the essence of defense in depth, not separation of duties. Separation of duties would require dividing critical tasks among different individuals to prevent fraud or error, which is not mentioned.

★ When this WOULD be the correct answer

A question where an organization splits database administration and security auditing roles between two different teams, or requires two people to approve changes to sensitive data, would make separation of duties the correct answer.

Why candidates choose this

Candidates may confuse 'separation of duties' with 'layered security' because both involve multiple controls, but separation of duties specifically addresses dividing responsibilities among people, not technical layers.

Fail safeWrong answer — click to see why

Why this is wrong here

The architect's strategy involves multiple overlapping controls (firewall, encryption, MFA, monitoring), which is the essence of defense in depth, not fail safe. Fail safe ensures that when a control fails, the system defaults to a secure state, which is not described here.

★ When this WOULD be the correct answer

A scenario where a security control is designed to default to a secure state upon failure, such as a door lock that remains locked during a power outage, or a firewall that blocks all traffic if it crashes, would make fail safe the correct answer.

Why candidates choose this

Candidates may confuse 'fail safe' with 'defense in depth' because both involve security measures, but fail safe specifically addresses system behavior during failures, not layered defenses.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security architect is designing the network security posture for a new branch office. The plan includes a next-generation firewall at the perimeter, an intrusion prevention system on the internal network, mandatory multi-factor authentication for all remote access, and quarterly security awareness training for employees. The architect explains that these controls are independent of each other so that a failure in any single control does not leave the entire network unprotected. Which security concept is the architect primarily implementing?

medium
  • A.Least privilege
  • B.Defense in depth
  • C.Zero trust
  • D.Separation of duties

Why B: The architect is implementing defense in depth by layering multiple independent security controls—a next-generation firewall (NGFW) at the perimeter, an intrusion prevention system (IPS) on the internal network, mandatory multi-factor authentication (MFA) for remote access, and quarterly security awareness training. The key phrase 'independent of each other so that a failure in any single control does not leave the entire network unprotected' directly describes the principle of layered defenses, where no single point of failure compromises overall security. This approach ensures that if an attacker bypasses the NGFW, the IPS or MFA may still prevent or detect the breach.

Variation 2. A security architect is designing a defense-in-depth strategy for a corporate network. Which of the following are fundamental principles or concepts that should be incorporated into this strategy? (Choose four.)

medium
  • .Layered security controls to provide redundancy and prevent a single point of failure
  • .Implementing a zero-trust model that assumes no implicit trust and requires continuous verification
  • .Disabling all logging and monitoring to reduce system resource consumption
  • .The principle of least privilege to limit user and system access to only what is necessary
  • .Using a single, comprehensive security solution to minimize complexity and management overhead
  • .Defining a separation of duties to prevent any single individual from having excessive control

Why : Defense-in-depth is a strategy that employs multiple layers of security controls to protect assets, ensuring redundancy and preventing a single point of failure. It also incorporates principles such as zero-trust (never trust, always verify), least privilege (granting only necessary access), and separation of duties (dividing responsibilities to reduce risk of abuse). Disabling logging and monitoring would reduce visibility and compromise security, while relying on a single comprehensive solution contradicts the layered approach.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.