Courseiva
Defense in Depth →mediumMultiple Select

GSEC Defense in Depth Practice Question

A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)

⚠ Common exam trap

The trap here is focusing on preventive controls like password policies or encryption when the scenario explicitly asks for detection improvements after a credential-based breach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploying host-based intrusion detection system (HIDS) agents on database servers

The breach exploited stolen credentials to access a database server, and the gaps were lack of host-based logging and database activity monitoring. HIDS agents provide host-level visibility into attacker actions, while DAM logs and alerts on suspicious database queries. Together they create detective controls that would likely have identified the unauthorized access. The other options are preventive or confidentiality controls that do not address the detection gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforcing a password complexity policy for all database accounts

    Why it's wrong here

    Password complexity reduces the risk of brute-force or guessing attacks, but the breach involved stolen credentials, so complexity would not have prevented it. It is a preventive control that does not address detection of future similar attacks. The scenario specifically calls for improving detection, not prevention.

  • ✓

    Deploying host-based intrusion detection system (HIDS) agents on database servers

    Why this is correct

    HIDS agents monitor host-level activity such as file changes, process execution, and unauthorized access attempts, providing visibility into attacker actions on the database server. This directly addresses the lack of host-based logging and would help detect similar credential-based intrusions. It adds a detective layer at the host level, complementing network controls.

  • ✓

    Implementing database activity monitoring (DAM) to log and alert on suspicious SQL queries

    Why this is correct

    DAM tools inspect database traffic and log queries, identifying unusual or unauthorized access patterns such as an attacker using stolen credentials to query sensitive tables. This fills the gap of unmonitored database activity and provides near-real-time alerts. It is a data-layer detective control that strengthens defense in depth.

  • ✗

    Implementing full-disk encryption on the database server

    Why it's wrong here

    Full-disk encryption protects data at rest if the disk is physically stolen, but it does not detect an attacker using valid credentials to access the database over the network. It is a preventive confidentiality control, not a detective one. The breach involved remote access, so encryption would not have helped detect or prevent it.

  • ✗

    Configuring a next-generation firewall to block outbound traffic from the database server

    Why it's wrong here

    Blocking outbound traffic can limit data exfiltration, but it does not provide detection of credential misuse or database activity. It is a preventive network control that may be useful but does not fill the stated logging and monitoring gaps. The investigation showed no host-based logging and no database monitoring, so detection controls are needed.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.