GSEC Defense in Depth Practice Question
A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?
⚠ Common exam trap
The trap here is assuming that logical access controls like NTFS permissions or firewalls can prevent physical access threats, when they only govern access through the operating system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption using BitLocker
The scenario requires a control that protects data even when an attacker has physical access to the server. Full disk encryption such as BitLocker encrypts the entire volume, rendering the data unreadable without the decryption key, regardless of user permissions or network controls. Thus, it provides a necessary layer in a defense in depth strategy for data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security auditing and log monitoring
Why it's wrong here
Auditing and monitoring are detective controls that record access attempts but do not prevent unauthorized access. They may alert after an incident but cannot stop an attacker with physical access from reading the data. Therefore, they do not meet the requirement of ensuring data confidentiality.
- ✗
Host-based firewall rules
Why it's wrong here
A host-based firewall filters network traffic to and from the server. It has no effect on data at rest or physical access. If an attacker has physical access, they can simply read the disk or boot offline, so firewall rules are irrelevant to this scenario.
- ✓
Full disk encryption using BitLocker
Why this is correct
BitLocker encrypts the entire volume, so if the server or its disks are physically stolen or accessed from another OS, the data remains unreadable without the recovery key. This directly addresses the risk of unauthorized physical access, adding a layer that protects data at rest independent of user authentication.
- ✗
NTFS permissions with least privilege
Why it's wrong here
NTFS permissions restrict access based on user or group identity when the OS is running. An attacker with physical access could boot from another OS or remove the disk and read it directly, bypassing NTFS. Thus, it does not protect against physical access as required.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.