GSEC · domain
Defense in Depth
Defense in Depth on GSEC covers layering preventive, detective, and corrective controls across hosts, networks, applications, and data. Questions present realistic scenarios—offsite tape handling, perimeter firewalls with VLAN segmentation, EHR architectures, Linux build pipelines—and ask you to select controls that reduce impact when one layer fails, including encryption, least privilege, and monitoring.
Focused practice
Practice Defense in Depth questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Defense in Depth
Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.
Applying full-disk or tape encryption (LUKS, BitLocker) so lost media cannot expose data
Using host-based firewalls, iptables/nftables, and VLAN segmentation to limit lateral movement
Deploying EDR, SIEM, and file integrity monitoring (AIDE, Tripwire) for detection layers
Hardening build servers with least privilege, sudo restrictions, SELinux/AppArmor, and network isolation
Watch out for
Common Defense in Depth exam traps
- ▸Treating defense in depth as simply buying more tools rather than ensuring independent layers that each address a distinct failure mode.
- ▸Assuming encryption alone protects data in use or that network segmentation replaces endpoint controls; candidates pick one control when the scenario needs layered answers.
- ▸Confusing detective controls (logging, IDS, EDR alerts) with preventive controls (firewalls, ACLs, encryption) when the question asks for a specific control category.
Question index
All Defense in Depth questions (20)
Click any question to see the full explanation, or start a practice session above.
A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?
Medium2A small financial firm has a flat network with no internal segmentation. The security team wants to apply defense in depth to limit the blast radius of a compromised workstation. Which action best aligns with that goal?
Easy3A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?
Medium4A retail company's e-commerce site is being targeted by credential stuffing attacks. The security team wants to add a control that slows automated login attempts while preserving a smooth experience for legitimate customers. Which control best fits this requirement?
Medium5Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?
Hard6When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?
Easy7Why does the inclusion of detective controls improve a defense in depth strategy?
Medium8Which of the following represents an example of applying defense in depth at the host level?
Medium9A government agency uses a defense in depth architecture with strict perimeter firewalls, network segmentation, and endpoint protection. During a red team exercise, attackers gained initial access via a phishing email and then moved laterally by exploiting a misconfigured internal server. The agency wants to improve its ability to detect and respond to such lateral movement. Which control would be most effective to add?
Hard10A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?
Medium11A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?
Easy12A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?
Hard13A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. During a purple-team exercise, analysts discover that a contractor's laptop, once connected to the internal network, can reach the HR payroll server directly over SMB. The security team wants to enforce the principle of least privilege on this internal traffic. Which control should they implement to best achieve this?
Medium14Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?
Medium15A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?
Hard16A software development company wants to protect its source code repositories from insider threats and external attackers. The company already uses network segmentation and endpoint detection. The security team proposes adding a control that requires two distinct factors before developers can access repositories, even from within the corporate network. Which control best meets this requirement?
Medium17Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?
Medium18A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)
Hard19A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)
Medium20An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Defense in Depth domain cover on the GSEC exam?
- Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.
- How many questions are in this domain?
- This page lists all 20 Defense in Depth questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Defense in Depth questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.