Courseiva
Defense in Depth →mediumMultiple Choice

GSEC Defense in Depth Practice Question

An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?

⚠ Common exam trap

Candidates often mistake this principle for least privilege or redundancy, confusing operational system fault tolerance with security-focused control layering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in Depth

Defense in depth uses layered security to ensure that if one control fails, others remain to mitigate risk. This strategy is critical because no single security measure is foolproof against sophisticated attackers. By diversifying controls across network, host, and data layers, the organization increases the attacker's workload and reduces the probability of a successful breach, ensuring that failures in one area do not lead to a catastrophic compromise of sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least Privilege

    Why it's wrong here

    Least privilege mandates that users and processes are granted only the minimum access rights necessary to perform their required tasks. While important for security, it focuses on limiting the scope of potential damage from a compromised identity rather than the layered control strategy defined by defense in depth.

  • ✗

    Security through Obscurity

    Why it's wrong here

    Security through obscurity relies on hiding information or system details to prevent attacks. This is generally considered a weak practice because attackers can discover hidden details through reconnaissance. It does not involve the structural layering of redundant controls that define the defense in depth architecture paradigm.

  • ✓

    Defense in Depth

    Why this is correct

    Defense in depth is an information security strategy that integrates multiple layers of security controls throughout an IT system. Its primary goal is to protect data by ensuring that if an attacker bypasses one defense, subsequent layers remain to prevent unauthorized access or minimize the overall impact.

  • ✗

    Fail-Safe Defaults

    Why it's wrong here

    Fail-safe defaults imply that in the event of a system failure, the security mechanism defaults to the most restrictive state, such as denying all access. This is an important security design principle, but it describes how a single control behaves rather than the layered defense architecture.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.