Courseiva

CCNA Defense in Depth Questions

20 questions · Defense in Depth · All types, answers revealed

1
MCQmedium

A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?

A.Security auditing and log monitoring
B.Host-based firewall rules
C.Full disk encryption using BitLocker
D.NTFS permissions with least privilege
AnswerC

BitLocker encrypts the entire volume, so if the server or its disks are physically stolen or accessed from another OS, the data remains unreadable without the recovery key. This directly addresses the risk of unauthorized physical access, adding a layer that protects data at rest independent of user authentication.

Why this answer

The scenario requires a control that protects data even when an attacker has physical access to the server. Full disk encryption such as BitLocker encrypts the entire volume, rendering the data unreadable without the decryption key, regardless of user permissions or network controls. Thus, it provides a necessary layer in a defense in depth strategy for data at rest.

Exam trap

The trap here is assuming that logical access controls like NTFS permissions or firewalls can prevent physical access threats, when they only govern access through the operating system.

2
MCQeasy

A small financial firm has a flat network with no internal segmentation. The security team wants to apply defense in depth to limit the blast radius of a compromised workstation. Which action best aligns with that goal?

A.Implementing 802.1X port-based network access control on all switch ports
B.Deploying a web application firewall (WAF) in front of the firm's public website
C.Enforcing strong password policies and multi-factor authentication for all users
D.Segmenting the network into VLANs based on function and applying ACLs between them
AnswerD

VLAN segmentation with inter-VLAN access control lists restricts traffic between network segments, so a compromised workstation in one VLAN cannot freely reach hosts in other VLANs. This directly limits lateral movement and reduces the blast radius, which is a core defense-in-depth principle. It adds an internal boundary that complements perimeter controls.

Why this answer

To limit the blast radius of a compromised workstation, the firm needs internal segmentation that restricts lateral movement. VLANs with inter-VLAN ACLs create logical boundaries so that a compromised host cannot freely access other segments. This is a classic defense-in-depth control that adds an internal layer beyond perimeter defenses.

Authentication and WAF controls address different threats and do not contain an internal compromise.

Exam trap

The trap here is confusing access control at the perimeter or authentication layer with internal containment; only segmentation limits what a compromised host can reach.

3
MCQmedium

A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?

A.Implementing full-disk encryption on the EHR database servers
B.File integrity monitoring (FIM) with cryptographic hashing on the EHR database files
C.Configuring syslog forwarding from the EHR servers to a central SIEM
D.Deploying an additional host-based firewall on the EHR application servers
AnswerB

FIM computes cryptographic hashes of critical files and compares them against a known-good baseline, so any unauthorized modification of EHR database records triggers an alert. This adds a detective control at the data layer, complementing existing preventive network and host controls. It directly addresses the need for near-real-time detection of record tampering without disrupting clinical workflows.

Why this answer

The scenario requires a detective control that specifically identifies unauthorized changes to EHR database records. File integrity monitoring with cryptographic hashing provides exactly that by comparing current file hashes to a trusted baseline and alerting on mismatch. The other options either duplicate existing preventive controls or provide logging without integrity detection, leaving the data-layer gap unaddressed.

Exam trap

The trap here is assuming that any logging or encryption control will detect data tampering, when only integrity-focused monitoring actually compares content against a known-good state.

4
MCQmedium

A retail company's e-commerce site is being targeted by credential stuffing attacks. The security team wants to add a control that slows automated login attempts while preserving a smooth experience for legitimate customers. Which control best fits this requirement?

A.Block all inbound traffic from countries where the company has no customers.
B.Deploy a CAPTCHA challenge after several failed login attempts from the same source.
C.Enforce a strict account lockout after three failed login attempts for all users.
D.Require all customers to use a hardware security key for authentication.
AnswerB

A CAPTCHA challenge presented after a threshold of failures forces automated tools to solve a human-verification task, breaking the economics of credential stuffing. Legitimate users who mistype a password a few times still pass through normally, so the customer experience is largely preserved. This is a targeted application-layer control.

Why this answer

Credential stuffing succeeds through automation, so the most effective layered control is one that imposes a human-verification cost after suspicious failure patterns. A CAPTCHA challenge achieves this while letting normal users proceed. Account lockout creates denial of service, hardware keys are impractical for retail customers, and geo-blocking is easily evaded and overly broad.

Exam trap

The trap here is choosing account lockout because it stops brute force, without recognizing that it enables attackers to lock out legitimate customers.

5
Multi-Selecthard

Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?

Select 3 answers
A.It restricts lateral movement for an attacker who has compromised a device.
B.It allows for the implementation of zone-specific access control lists.
C.It eliminates the need for host-based firewalls on individual servers.
D.It facilitates better logging and monitoring of inter-zone traffic.
E.It automatically encrypts all data in transit between segments.
AnswersA, B, D

If a workstation is compromised, segmentation limits the attacker's ability to scan or connect to other network segments. By placing servers in a separate VLAN from end-user devices, the organization forces the attacker to find another way to move through the network, adding friction to the attack.

Why this answer

Network segmentation breaks a flat network into smaller, isolated subnets. This limits the blast radius of a breach by preventing lateral movement, restricting access to sensitive data, and providing points to inspect traffic between zones. By enforcing boundaries, the organization ensures that an attacker who compromises a workstation in one zone cannot easily pivot to critical servers in another, thus creating multiple functional barriers that the attacker must overcome to reach the high-value targets.

Exam trap

Candidates often select options related to 'network performance' or 'bandwidth optimization,' which are irrelevant to the security objectives of defense in depth and lateral movement prevention.

6
MCQeasy

When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?

A.To reduce the overall cost of software licensing and maintenance.
B.To ensure that a single vulnerability does not bypass all defense layers.
C.To simplify the process of configuring and managing security logs.
D.To minimize the need for external security audits and compliance checks.
AnswerB

Heterogeneous controls prevent single points of failure. If all layers used the same technology, a single zero-day exploit could potentially compromise every layer simultaneously. Diversity ensures that an attacker must possess multiple, distinct exploits to traverse the various security layers, drastically increasing the difficulty for the adversary.

Why this answer

Heterogeneous controls provide diversity, ensuring that a single flaw or vulnerability in one vendor's product does not compromise the entire defense. In a homogeneous environment, if an attacker discovers a bypass for one control, they can apply that same technique across all layers. Using different technologies or vendors increases the probability that at least one layer will successfully stop the threat, thereby making the overall environment significantly more resilient against targeted attacks.

Exam trap

Candidates often think heterogeneity is for 'performance' or 'cost reduction.' They fail to grasp that the primary security goal is to prevent a single vendor's vulnerability from compromising every layer.

7
MCQmedium

Why does the inclusion of detective controls improve a defense in depth strategy?

A.They automatically block all malicious traffic before it reaches the network.
B.They provide visibility into successful bypasses of preventive controls.
C.They remove the need for regular vulnerability assessments.
D.They ensure that all user actions are strictly restricted by policy.
AnswerB

No preventive control is 100% effective. Detective controls like IDS, log analysis, and file integrity monitoring provide the necessary visibility to identify when a preventive control has failed. This allows the security team to act quickly, minimizing the damage caused by an attacker who has successfully gained unauthorized access.

Why this answer

Preventive controls are not always effective against every threat; therefore, detective controls are necessary to identify breaches that successfully penetrate the perimeter. By monitoring for indicators of compromise, security teams can respond to incidents in progress. This reduces the dwell time of an attacker, preventing a minor initial compromise from escalating into a major data exfiltration event.

Detective controls effectively close the loop between prevention and response in a defense in depth model.

Exam trap

Candidates often assume detective controls prevent breaches. They confuse the role of detection with prevention, failing to realize that detective controls identify failures rather than stop the initial unauthorized access attempt.

8
MCQmedium

Which of the following represents an example of applying defense in depth at the host level?

A.Installing a web application firewall at the network edge.
B.Configuring local host firewalls and endpoint detection and response (EDR) software.
C.Implementing multi-factor authentication for corporate VPN access.
D.Deploying a network intrusion detection system (NIDS) in promiscuous mode.
AnswerB

These two tools together at the host level create a layer of defense that operates independently of network-wide controls. The host firewall limits incoming and outgoing traffic, while EDR provides continuous monitoring and threat prevention for local processes, effectively creating a defense in depth posture on the machine.

Why this answer

Host-level defense in depth involves implementing multiple security controls directly on individual servers or workstations to create a resilient environment. If an attacker bypasses the network perimeter, host-based controls like EDR and local firewalls provide the final barrier. This multi-faceted approach ensures that even if a network segment is compromised, the specific endpoint remains protected and monitored, preventing widespread damage and aiding in rapid incident response and threat isolation.

Exam trap

Candidates often pick network-based controls like firewalls or IDS. The question specifically asks for 'host-level' defense, requiring controls that exist directly on the endpoint itself.

9
MCQhard

A government agency uses a defense in depth architecture with strict perimeter firewalls, network segmentation, and endpoint protection. During a red team exercise, attackers gained initial access via a phishing email and then moved laterally by exploiting a misconfigured internal server. The agency wants to improve its ability to detect and respond to such lateral movement. Which control would be most effective to add?

A.Enforcing application whitelisting on all endpoints
B.Increasing the perimeter firewall rule set to block more inbound ports
C.Deploying network-based intrusion detection system (NIDS) sensors on internal network segments
D.Implementing stricter email filtering to prevent phishing emails
AnswerC

NIDS sensors on internal segments monitor east-west traffic for malicious patterns, such as exploit attempts and unusual lateral movement. This directly addresses the gap that allowed attackers to move internally after initial compromise. It adds a detective layer inside the network, complementing perimeter defenses and endpoint controls.

Why this answer

Lateral movement occurs inside the network after initial compromise, so detection requires visibility into internal traffic. NIDS sensors on internal segments can identify exploit attempts, scanning, and unusual communication patterns between hosts. Perimeter and email controls address initial access, while application whitelisting is host-focused and may not detect network-based movement.

Internal NIDS fills the specific gap highlighted by the red team exercise.

Exam trap

The trap here is assuming that strengthening perimeter or email defenses will detect internal lateral movement, when those controls operate at the boundary and do not see east-west traffic.

10
MCQmedium

A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?

A.Configure private VLANs to prevent hosts within the cardholder data environment from communicating with each other.
B.Deploy a web application firewall (WAF) in front of the cardholder data environment.
C.Enable 802.1X port-based network access control on all switch ports in both VLANs.
D.Install a network intrusion detection system (NIDS) with a span port monitoring traffic between the VLANs.
AnswerD

A NIDS receiving a copy of inter-segment traffic via a SPAN port analyzes packets for known attack signatures and anomalies. If malicious traffic crosses the segmentation boundary, the NIDS raises an alert, providing the detective layer the architect wants. It does not block traffic, which matches the requirement for detection rather than prevention.

Why this answer

The architect needs visibility into traffic that crosses the segmentation boundary, which is a detective control function. A network intrusion detection system monitoring a SPAN port sees copies of packets traversing the inter-VLAN link and can alert on malicious patterns. WAFs, 802.1X, and private VLANs either focus on web traffic or enforce preventive access restrictions, none of which detect successful cross-segment intrusions.

Exam trap

The trap here is confusing segmentation enforcement controls with monitoring controls, when the scenario explicitly asks for detection after traffic already crosses a boundary.

11
MCQeasy

A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?

A.Configure Windows Audit Policy to log all file access events to the Security event log.
B.Enable Windows BitLocker full-disk encryption on the billing server's data volume.
C.Deploy a host-based intrusion prevention system (HIPS) that blocks suspicious process execution on the billing server.
D.Implement file integrity monitoring (FIM) using SHA-256 hashes of the claim files and schedule regular baseline comparisons.
AnswerD

File integrity monitoring computes cryptographic hashes of the claim files and stores a known-good baseline. On subsequent scans, any modification produces a hash mismatch, alerting the team even if the attacker used legitimate administrative privileges. This directly satisfies the requirement to detect unauthorized modification independently of access controls.

Why this answer

Detecting unauthorized modification of stored data requires a mechanism that can prove whether contents changed, regardless of the attacker's privilege level. Hash-based file integrity monitoring establishes a trusted baseline and alerts on any deviation, which is exactly what the hospital needs. Encryption and auditing address confidentiality and visibility respectively, and neither produces cryptographic evidence of tampering.

Exam trap

The trap here is assuming that administrative access logging or disk encryption will reveal file tampering, when only a hash-based baseline comparison can prove content changes.

12
MCQhard

A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?

A.Encrypt the backup tapes using AES-256 with keys managed separately from the tapes.
B.Require the courier to sign a non-disclosure agreement and provide chain-of-custody documentation.
C.Install GPS trackers on the transport vehicle and monitor the route in real time.
D.Reduce the backup retention period from one year to thirty days to limit exposure.
AnswerA

Encrypting the tapes with AES-256 renders the data unreadable without the key, so a lost or stolen tape does not expose customer information. Managing keys separately from the tapes ensures the key is not lost with the media. This is the direct technical control that addresses the confidentiality risk described.

Why this answer

The risk is that a lost or stolen tape exposes customer data, so the control must make the data unreadable without authorization. Encrypting tapes with AES-256 and storing keys separately achieves this directly. NDAs, GPS tracking, and shorter retention periods address accountability, recovery, or exposure windows but leave the tape contents readable if the media falls into the wrong hands.

Exam trap

The trap here is selecting administrative or physical controls that improve accountability or tracking while leaving the actual data on the tape unprotected.

13
MCQmedium

A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. During a purple-team exercise, analysts discover that a contractor's laptop, once connected to the internal network, can reach the HR payroll server directly over SMB. The security team wants to enforce the principle of least privilege on this internal traffic. Which control should they implement to best achieve this?

A.Deploy an intrusion prevention system (IPS) on the internal network to block SMB exploits.
B.Implement internal microsegmentation with host-based firewall rules that allow only authorized HR subnets to reach the payroll server on TCP 445.
C.Enable port security on the access switch to limit the number of MAC addresses per port.
D.Configure the perimeter firewall to block all inbound SMB traffic from the internet.
AnswerB

Microsegmentation enforces least privilege by defining granular allow rules between workloads. Restricting SMB access to only the HR subnet prevents the contractor's laptop, which resides elsewhere, from reaching the payroll server, even though it is on the internal network. This directly addresses the lateral movement path discovered in the exercise and aligns with defense in depth at the host and network layers.

Why this answer

The contractor's laptop is an internal host, so perimeter and network-based detective controls do not stop it from reaching the payroll server. Microsegmentation with host-based firewall rules enforces least privilege by permitting only the HR subnet to use SMB against that server. This limits lateral movement and adds a granular layer of defense that complements existing perimeter and segmentation controls.

Exam trap

The trap here is assuming that perimeter firewalls and VLANs alone enforce least privilege internally, when in fact east-west traffic between VLANs or within a flat segment can still allow unauthorized access.

14
MCQmedium

Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?

A.Zero Trust Architecture
B.Defense in Depth
C.Security Information and Event Management (SIEM)
D.Privileged Access Management (PAM)
AnswerB

Defense in depth is the systematic application of security controls across multiple layers, including perimeter, network, host, application, and data. This layered approach ensures that if a control at one layer fails or is bypassed, subsequent layers are in place to stop the attacker or limit damage.

Why this answer

This approach is the definition of defense in depth, which utilizes multiple layers of security across the entire IT stack. By distributing controls across these distinct layers, an organization ensures that there are multiple obstacles between an attacker and the sensitive data. This holistic coverage is essential because attackers often use multi-stage campaigns, and having defenses at every level allows for detection and interception at different phases of the attack lifecycle.

Exam trap

Candidates often select zero trust or perimeter security, confusing modern holistic architectural frameworks with the fundamental multi-layered control concept described in the scenario.

15
MCQhard

A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?

A.Heterogeneous controls reduce licensing costs because multiple vendors compete for the same functionality.
B.Using different vendors ensures that a single exploit or misconfiguration cannot simultaneously compromise all layers of defense.
C.Different vendors provide more comprehensive log formats that are easier to correlate in the SIEM.
D.Heterogeneous controls are required by HIPAA for any system that stores electronic protected health information.
AnswerB

Heterogeneous controls mean that a vulnerability, bug, or misconfiguration in one product is unlikely to affect another from a different vendor. If an attacker discovers a bypass in one firewall brand, the EDR or SIEM from another vendor may still detect or block the activity. This diversity creates independent failure domains, which is a core principle of defense in depth and directly supports the architect's recommendation.

Why this answer

Heterogeneous security controls create independent failure domains. If one vendor's product has a vulnerability or is misconfigured, the others are unlikely to share the same flaw, so a single exploit cannot disable all layers. This diversity strengthens defense in depth by preventing common-mode failures, which is the architect's core justification for mixing vendors in the EHR environment.

Exam trap

The trap here is confusing vendor diversity with cost savings or regulatory mandates, when the real security benefit is reducing the risk of a single flaw compromising multiple defensive layers.

16
MCQmedium

A software development company wants to protect its source code repositories from insider threats and external attackers. The company already uses network segmentation and endpoint detection. The security team proposes adding a control that requires two distinct factors before developers can access repositories, even from within the corporate network. Which control best meets this requirement?

A.Deploying a bastion host that developers must use to reach repositories
B.Enforcing role-based access control (RBAC) on repositories
C.Implementing multi-factor authentication (MFA) for repository access
D.Configuring IP allowlisting for repository access
AnswerC

MFA requires two or more distinct authentication factors, such as a password plus a hardware token, before granting access. This directly meets the requirement of requiring two distinct factors even from inside the network. It adds an identity-layer control that strengthens defense in depth against credential theft and insider misuse.

Why this answer

The requirement is to require two distinct authentication factors before granting repository access, even from inside the corporate network. Multi-factor authentication is the only option that provides this by combining something the user knows with something they have or are. Bastion hosts, RBAC, and IP allowlisting are valuable defense-in-depth controls but do not enforce two-factor authentication on their own.

Exam trap

The trap here is confusing access control mechanisms like RBAC or bastion hosts with authentication factors; only MFA enforces two distinct factors.

17
Multi-Selectmedium

Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?

Select 2 answers
A.To eliminate the need for regular security patching.
B.To increase the difficulty and cost for an attacker to succeed.
C.To ensure that a single control failure does not result in a breach.
D.To replace the requirement for user security awareness training.
E.To centralize all logs into a single storage location.
AnswersB, C

By implementing multiple, heterogeneous layers of security, an organization forces an attacker to expend more time and resources. Each additional layer increases the complexity of the attack chain, raising the likelihood of detection and providing more opportunities for the security team to identify and stop the adversary.

Why this answer

Defense in depth aims to delay attackers, increase the probability of detection, and ensure that a single point of failure does not lead to a total security compromise. These objectives are achieved by creating layers that require an attacker to defeat multiple, distinct security measures. This approach is essential for modern enterprises where perimeter defenses can be bypassed via phishing or zero-day vulnerabilities, making internal detection and mitigation capabilities absolutely vital.

Exam trap

Candidates often select incorrect options that imply defense in depth can completely prevent all initial attacks or eliminate risk entirely, rather than merely increasing cost and resilience.

18
Multi-Selecthard

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

Select 3 answers
A.Grant the build service account passwordless sudo access to all commands to simplify automation.
B.Require all build servers to authenticate users with individual SSH keys and disable password authentication.
C.Disable SELinux on the build server to avoid build failures caused by mandatory access control denials.
D.Store build signing keys on a hardware security module (HSM) that requires dual authorization to use.
E.Run build jobs inside containers that drop all Linux capabilities and use a read-only root filesystem.
AnswersB, D, E

Per-user SSH keys with password authentication disabled prevent credential reuse and brute-force attacks against the build host. Individual keys create accountability and allow revocation without disrupting other engineers. This strengthens identity controls at the host layer, making initial compromise harder and limiting attacker movement.

Why this answer

Reducing the impact of a compromised build server requires layered constraints: container isolation with dropped capabilities and read-only filesystems limits what code can do, HSM-backed signing keys with dual authorization protect the supply chain, and per-user SSH keys harden initial access. Disabling SELinux and granting unrestricted sudo both expand attacker privileges, so they weaken rather than strengthen the layered defense.

Exam trap

The trap here is treating convenience measures such as disabling SELinux or granting broad sudo as acceptable hardening, when they actually remove layers of defense.

19
Multi-Selectmedium

A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)

Select 2 answers
A.Enforcing a password complexity policy for all database accounts
B.Deploying host-based intrusion detection system (HIDS) agents on database servers
C.Implementing database activity monitoring (DAM) to log and alert on suspicious SQL queries
D.Implementing full-disk encryption on the database server
E.Configuring a next-generation firewall to block outbound traffic from the database server
AnswersB, C

HIDS agents monitor host-level activity such as file changes, process execution, and unauthorized access attempts, providing visibility into attacker actions on the database server. This directly addresses the lack of host-based logging and would help detect similar credential-based intrusions. It adds a detective layer at the host level, complementing network controls.

Why this answer

The breach exploited stolen credentials to access a database server, and the gaps were lack of host-based logging and database activity monitoring. HIDS agents provide host-level visibility into attacker actions, while DAM logs and alerts on suspicious database queries. Together they create detective controls that would likely have identified the unauthorized access.

The other options are preventive or confidentiality controls that do not address the detection gap.

Exam trap

The trap here is focusing on preventive controls like password policies or encryption when the scenario explicitly asks for detection improvements after a credential-based breach.

20
MCQmedium

An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?

A.Least Privilege
B.Security through Obscurity
C.Defense in Depth
D.Fail-Safe Defaults
AnswerC

Defense in depth is an information security strategy that integrates multiple layers of security controls throughout an IT system. Its primary goal is to protect data by ensuring that if an attacker bypasses one defense, subsequent layers remain to prevent unauthorized access or minimize the overall impact.

Why this answer

Defense in depth uses layered security to ensure that if one control fails, others remain to mitigate risk. This strategy is critical because no single security measure is foolproof against sophisticated attackers. By diversifying controls across network, host, and data layers, the organization increases the attacker's workload and reduces the probability of a successful breach, ensuring that failures in one area do not lead to a catastrophic compromise of sensitive information.

Exam trap

Candidates often mistake this principle for least privilege or redundancy, confusing operational system fault tolerance with security-focused control layering.

Ready to test yourself?

Try a timed practice session using only Defense in Depth questions.