Courseiva
Defense in Depth →mediumMultiple Choice

GSEC Defense in Depth Practice Question

Which of the following represents an example of applying defense in depth at the host level?

⚠ Common exam trap

Candidates often pick network-based controls like firewalls or IDS. The question specifically asks for 'host-level' defense, requiring controls that exist directly on the endpoint itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuring local host firewalls and endpoint detection and response (EDR) software.

Host-level defense in depth involves implementing multiple security controls directly on individual servers or workstations to create a resilient environment. If an attacker bypasses the network perimeter, host-based controls like EDR and local firewalls provide the final barrier. This multi-faceted approach ensures that even if a network segment is compromised, the specific endpoint remains protected and monitored, preventing widespread damage and aiding in rapid incident response and threat isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Installing a web application firewall at the network edge.

    Why it's wrong here

    A WAF deployed at the network edge is a perimeter-level control designed to inspect traffic before it reaches the internal network. While effective for filtering web traffic, it does not provide protection directly on the host itself, which is the defining requirement for a host-level defense control.

  • ✓

    Configuring local host firewalls and endpoint detection and response (EDR) software.

    Why this is correct

    These two tools together at the host level create a layer of defense that operates independently of network-wide controls. The host firewall limits incoming and outgoing traffic, while EDR provides continuous monitoring and threat prevention for local processes, effectively creating a defense in depth posture on the machine.

  • ✗

    Implementing multi-factor authentication for corporate VPN access.

    Why it's wrong here

    MFA for VPN access is a strong identity and access management control, but it is applied at the network perimeter or the identity provider layer. It helps secure entry into the network, but it does not represent a control applied locally to an endpoint to provide host-level defense.

  • ✗

    Deploying a network intrusion detection system (NIDS) in promiscuous mode.

    Why it's wrong here

    A NIDS is a network-level security control that monitors traffic traversing the network segments. It is not an endpoint or host-based security control. While it is part of an overall defense in depth architecture, it does not satisfy the requirement for security controls deployed specifically on the host.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.