Courseiva
Defense in Depth →mediumMultiple Choice

GSEC Defense in Depth Practice Question

A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?

⚠ Common exam trap

The trap here is assuming that logical access controls like NTFS permissions or firewalls can prevent physical access threats, when they only govern access through the operating system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Full disk encryption using BitLocker

The scenario requires a control that protects data even when an attacker has physical access to the server. Full disk encryption such as BitLocker encrypts the entire volume, rendering the data unreadable without the decryption key, regardless of user permissions or network controls. Thus, it provides a necessary layer in a defense in depth strategy for data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security auditing and log monitoring

    Why it's wrong here

    Auditing and monitoring are detective controls that record access attempts but do not prevent unauthorized access. They may alert after an incident but cannot stop an attacker with physical access from reading the data. Therefore, they do not meet the requirement of ensuring data confidentiality.

  • ✗

    Host-based firewall rules

    Why it's wrong here

    A host-based firewall filters network traffic to and from the server. It has no effect on data at rest or physical access. If an attacker has physical access, they can simply read the disk or boot offline, so firewall rules are irrelevant to this scenario.

  • ✓

    Full disk encryption using BitLocker

    Why this is correct

    BitLocker encrypts the entire volume, so if the server or its disks are physically stolen or accessed from another OS, the data remains unreadable without the recovery key. This directly addresses the risk of unauthorized physical access, adding a layer that protects data at rest independent of user authentication.

  • ✗

    NTFS permissions with least privilege

    Why it's wrong here

    NTFS permissions restrict access based on user or group identity when the OS is running. An attacker with physical access could boot from another OS or remove the disk and read it directly, bypassing NTFS. Thus, it does not protect against physical access as required.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.