Courseiva

GSEC · topic practice

Defense in Depth practice questions

Defense in Depth on GSEC covers layering preventive, detective, and corrective controls across hosts, networks, applications, and data. Questions present realistic scenarios—offsite tape handling, perimeter firewalls with VLAN segmentation, EHR architectures, Linux build pipelines—and ask you to select controls that reduce impact when one layer fails, including encryption, least privilege, and monitoring.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Defense in Depth

What the exam tests

What to know about Defense in Depth

Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.

Applying full-disk or tape encryption (LUKS, BitLocker) so lost media cannot expose data

Using host-based firewalls, iptables/nftables, and VLAN segmentation to limit lateral movement

Deploying EDR, SIEM, and file integrity monitoring (AIDE, Tripwire) for detection layers

Hardening build servers with least privilege, sudo restrictions, SELinux/AppArmor, and network isolation

Watch out for

Common Defense in Depth exam traps

  • ▸Treating defense in depth as simply buying more tools rather than ensuring independent layers that each address a distinct failure mode.
  • ▸Assuming encryption alone protects data in use or that network segmentation replaces endpoint controls; candidates pick one control when the scenario needs layered answers.
  • ▸Confusing detective controls (logging, IDS, EDR alerts) with preventive controls (firewalls, ACLs, encryption) when the question asks for a specific control category.

Practice set

Defense in Depth questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Open the full VLAN trunking answer →

An enterprise network implements perimeter firewalls, host-based firewalls, internal VLAN segmentation, and endpoint detection agents. Despite this multi-layered defense, an attacker successfully exfiltrates data through an unmonitored external cloud storage provider via standard HTTPS. Which security control principle was primarily neglected in this defense-in-depth architecture?

Question 2mediummultiple choice
Read the full Defense in Depth explanation →

An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?

Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?

Question 4mediummultiple choice
Read the full Defense in Depth explanation →

Which of the following represents an example of applying defense in depth at the host level?

When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?

Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?

Question 7mediummultiple choice
Read the full Defense in Depth explanation →

Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?

Question 8mediummultiple choice
Read the full Defense in Depth explanation →

Why does the inclusion of detective controls improve a defense in depth strategy?

Question 9mediummultiple choice
Open the full VLAN trunking answer →

A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. During a purple-team exercise, analysts discover that a contractor's laptop, once connected to the internal network, can reach the HR payroll server directly over SMB. The security team wants to enforce the principle of least privilege on this internal traffic. Which control should they implement to best achieve this?

A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?

Question 11mediummultiple choice
Read the full Defense in Depth explanation →

A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?

A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?

Question 13easymultiple choice
Study the full AAA explanation →

A small financial firm has a flat network with no internal segmentation. The security team wants to apply defense in depth to limit the blast radius of a compromised workstation. Which action best aligns with that goal?

Question 14mediummultiple choice
Open the full VLAN trunking answer →

A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?

A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

A government agency uses a defense in depth architecture with strict perimeter firewalls, network segmentation, and endpoint protection. During a red team exercise, attackers gained initial access via a phishing email and then moved laterally by exploiting a misconfigured internal server. The agency wants to improve its ability to detect and respond to such lateral movement. Which control would be most effective to add?

Question 18mediummultiple choice
Read the full Defense in Depth explanation →

A retail company's e-commerce site is being targeted by credential stuffing attacks. The security team wants to add a control that slows automated login attempts while preserving a smooth experience for legitimate customers. Which control best fits this requirement?

Question 19mediummultiple choice
Read the full Defense in Depth explanation →

A software development company wants to protect its source code repositories from insider threats and external attackers. The company already uses network segmentation and endpoint detection. The security team proposes adding a control that requires two distinct factors before developers can access repositories, even from within the corporate network. Which control best meets this requirement?

A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Defense in Depth sessions

Start a Defense in Depth only practice session

Every question in these sessions is drawn from the Defense in Depth domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Defense in Depth?
Identify which layer fails in the scenario, then choose controls that prevent, detect, or contain that failure without relying on a single mechanism. The key skill is mapping encryption, segmentation, least privilege, and monitoring to the exact asset and threat described.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Defense in Depth questions in a focused session?
Yes — the session launcher on this page draws every question from the Defense in Depth domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.