Courseiva
Question 362 of 1,013
General Security ConceptsmediumMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

A security architect proposes adding endpoint protection, network segmentation, multifactor authentication, email filtering, and immutable backups so that one failed safeguard does not expose the entire organization. What security strategy is being described?

⚠ Common exam trap

It's easy for candidates to confuse 'defense in depth' with 'least privilege' because both involve multiple controls, but defense in depth specifically requires overlapping, independent layers rather than just restricting permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Defense in depth

Defense in depth is a layered security strategy where multiple, independent controls (endpoint protection, network segmentation, MFA, email filtering, immutable backups) are deployed so that if one safeguard fails, others continue to protect the organization. This approach ensures no single point of failure can compromise the entire environment, aligning directly with the scenario described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why this is correct

    Defense in depth uses multiple independent controls so that if one layer fails, others still reduce the chance of compromise or limit the damage. The mix of endpoint, network, identity, email, and recovery controls in the scenario is a textbook layered approach. It is especially useful because attackers rarely defeat every safeguard at once.

  • Least privilege

    Why it's wrong here

    Least privilege is a design principle that limits users and processes to the minimum permissions required to perform their job function, typically enforced through IAM roles, group policies, and access control lists. The scenario, however, describes adding endpoint protection to an existing stack of network, identity, email, and recovery controls—an architecture that derives strength from overlapping independent defenses, not from restricting privileges. Least privilege might be a component within one of those layers, but it cannot explain why combining multiple different control types provides resilience against failure or bypass.

  • Need-to-know

    Why it's wrong here

    Need-to-know is an information handling rule that restricts access to specific data based on an individual's official duties, preventing unnecessary disclosure of sensitive information. The question focuses on a security architect proposing endpoint protection network controls alongside other layered safeguards, which is about mitigating threats across the environment rather than limiting data visibility. While need-to-know could inform an authorization decision inside an access control layer, it does not describe the overall strategy of stacking endpoint, network, identity, email, and recovery defenses to resist compromise.

  • Zero trust

    Why it's wrong here

    Zero trust is an access-centric security model that rejects implicit trust and continuously validates every request based on identity, device posture, and context, often using microsegmentation and conditional access policies. Although a zero trust architecture can incorporate multiple enforcement points, the scenario specifically highlights adding endpoint protection to a suite of diverse controls—a textbook defense in depth approach focused on redundancy and survivability across layers. Zero trust emphasizes 'never trust, always verify' for each transaction, whereas the correct answer stresses the combined effect of multiple independent layers that protect even when one is breached.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.