Courseiva
General Security ConceptsmediumMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

After a successful phishing attempt, the security team adds MFA, email sandboxing, endpoint isolation, and immutable backups so that one failed safeguard does not expose the company. Which principle does this best illustrate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Defense in depth

Defense in depth is the best fit because the organization is using several independent safeguards across different layers: user authentication, email inspection, endpoint containment, and backup recovery. The idea is that a single compromise, such as one successful phishing email, should not lead directly to full compromise. Security+ expects you to recognize layered protection as a strategy, not just list individual tools. Why others are wrong: Need-to-know concerns restricting information to only those who require it for their job. Availability is one of the CIA triad objectives, but it is not a layered security strategy. Compensating control refers to an alternative measure used because the preferred control is unavailable or impractical; here the organization is not replacing one missing control, but strengthening multiple defenses at once.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why this is correct

    Adding MFA after a successful phishing attack exemplifies defense in depth because the security team is introducing an additional, independent control layer beyond passwords. If a user's credentials are compromised via phishing, the attacker still lacks the second factor (e.g., a time-based one-time code or hardware key), thereby preventing unauthorized access. This strategy assumes no single control is fail-proof and employs overlapping safeguards—such as email filtering, security awareness training, and MFA—to reduce overall risk when any one control fails.

  • Need-to-know

    Why it's wrong here

    Need-to-know is an access control principle that restricts data access to only those individuals whose job responsibilities require that specific information. It does not describe the layered security architecture demonstrated by adding MFA after a phishing incident. MFA is an authentication mechanism that verifies a user's identity, not a policy for limiting what data a user can view or modify. Therefore, this option is incorrect because it addresses information confidentiality boundaries rather than defense-in-depth control stacking.

  • Availability

    Why it's wrong here

    Availability is a core security objective ensuring that systems and data remain accessible to authorized users when needed. While adding MFA can introduce a slight authentication delay or friction, the principle being exercised after a phishing attack is not about uptime or resilience to denial-of-service. The security team is not designing for availability; they are layering an additional identity verification step to prevent compromise. Thus, this option is wrong because availability is a security goal, not a defensive design strategy that explains the MFA addition.

  • Compensating control

    Why it's wrong here

    A compensating control is an alternative safeguard implemented when an organization cannot meet a specific security requirement due to technical or operational constraints, effectively substituting for the missing control. In this scenario, MFA is not replacing an absent control; it is being added on top of existing defenses such as spam filters and user training after a breach. The intent is to create redundancy through multiple layers, which is the hallmark of defense in depth, not to compensate for an unmet requirement. Therefore, it is incorrect because compensating controls address a single gap, whereas this action strengthens the overall security posture.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.