SY0-701 General Security Concepts Practice Question
A security architect proposes adding endpoint protection, network segmentation, multifactor authentication, email filtering, and immutable backups so that one failed safeguard does not expose the entire organization. What security strategy is being described?
⚠ Common exam trap
It's easy for candidates to confuse 'defense in depth' with 'least privilege' because both involve multiple controls, but defense in depth specifically requires overlapping, independent layers rather than just restricting permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
Defense in depth is a layered security strategy where multiple, independent controls (endpoint protection, network segmentation, MFA, email filtering, immutable backups) are deployed so that if one safeguard fails, others continue to protect the organization. This approach ensures no single point of failure can compromise the entire environment, aligning directly with the scenario described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defense in depth
Why this is correct
Defense in depth uses multiple independent controls so that if one layer fails, others still reduce the chance of compromise or limit the damage. The mix of endpoint, network, identity, email, and recovery controls in the scenario is a textbook layered approach. It is especially useful because attackers rarely defeat every safeguard at once.
- ✗
Least privilege
Why it's wrong here
Least privilege is a design principle that limits users and processes to the minimum permissions required to perform their job function, typically enforced through IAM roles, group policies, and access control lists. The scenario, however, describes adding endpoint protection to an existing stack of network, identity, email, and recovery controls—an architecture that derives strength from overlapping independent defenses, not from restricting privileges. Least privilege might be a component within one of those layers, but it cannot explain why combining multiple different control types provides resilience against failure or bypass.
- ✗
Need-to-know
Why it's wrong here
Need-to-know is an information handling rule that restricts access to specific data based on an individual's official duties, preventing unnecessary disclosure of sensitive information. The question focuses on a security architect proposing endpoint protection network controls alongside other layered safeguards, which is about mitigating threats across the environment rather than limiting data visibility. While need-to-know could inform an authorization decision inside an access control layer, it does not describe the overall strategy of stacking endpoint, network, identity, email, and recovery defenses to resist compromise.
- ✗
Zero trust
Why it's wrong here
Zero trust is an access-centric security model that rejects implicit trust and continuously validates every request based on identity, device posture, and context, often using microsegmentation and conditional access policies. Although a zero trust architecture can incorporate multiple enforcement points, the scenario specifically highlights adding endpoint protection to a suite of diverse controls—a textbook defense in depth approach focused on redundancy and survivability across layers. Zero trust emphasizes 'never trust, always verify' for each transaction, whereas the correct answer stresses the combined effect of multiple independent layers that protect even when one is breached.
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Network segmentation
Network segmentation is the practice of dividing a computer network into smaller, isolated parts to improve performance, contain security threats, and simplify management.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.