Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?
By implementing multiple, heterogeneous layers of security, an organization forces an attacker to expend more time and resources. Each additional layer increases the complexity of the attack chain, raising the likelihood of detection and providing more opportunities for the security team to identify and stop the adversary.
Why this answer
Defense in depth aims to delay attackers, increase the probability of detection, and ensure that a single point of failure does not lead to a total security compromise. These objectives are achieved by creating layers that require an attacker to defeat multiple, distinct security measures. This approach is essential for modern enterprises where perimeter defenses can be bypassed via phishing or zero-day vulnerabilities, making internal detection and mitigation capabilities absolutely vital.
Exam trap
Candidates often select incorrect options that imply defense in depth can completely prevent all initial attacks or eliminate risk entirely, rather than merely increasing cost and resilience.