GSEC Defense in Depth Practice Question
Why does the inclusion of detective controls improve a defense in depth strategy?
⚠ Common exam trap
Candidates often assume detective controls prevent breaches. They confuse the role of detection with prevention, failing to realize that detective controls identify failures rather than stop the initial unauthorized access attempt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They provide visibility into successful bypasses of preventive controls.
Preventive controls are not always effective against every threat; therefore, detective controls are necessary to identify breaches that successfully penetrate the perimeter. By monitoring for indicators of compromise, security teams can respond to incidents in progress. This reduces the dwell time of an attacker, preventing a minor initial compromise from escalating into a major data exfiltration event. Detective controls effectively close the loop between prevention and response in a defense in depth model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They automatically block all malicious traffic before it reaches the network.
Why it's wrong here
Detective controls are designed to alert and provide visibility, not to block traffic. Preventive controls are the ones responsible for blocking malicious activity. Misunderstanding the function of detective controls can lead to a false sense of security regarding the organization's ability to stop active threats in real time.
- ✓
They provide visibility into successful bypasses of preventive controls.
Why this is correct
No preventive control is 100% effective. Detective controls like IDS, log analysis, and file integrity monitoring provide the necessary visibility to identify when a preventive control has failed. This allows the security team to act quickly, minimizing the damage caused by an attacker who has successfully gained unauthorized access.
- ✗
They remove the need for regular vulnerability assessments.
Why it's wrong here
Detective controls do not address the root causes of vulnerabilities. Regular vulnerability assessments are essential to identify and remediate weaknesses in the environment. Relying on detection to manage vulnerabilities is an inefficient and high-risk strategy that fails to address the underlying security issues present in the network.
- ✗
They ensure that all user actions are strictly restricted by policy.
Why it's wrong here
Detective controls monitor actions but do not restrict them based on policy; that is the role of access control and preventive policy enforcement. Confusing detection with enforcement is a common mistake that undermines the effectiveness of an organization's security posture by failing to implement necessary preventive measures.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.