Courseiva
Google Cloud Security →easyMultiple Choice

Cloud Digital Leader Google Cloud Security Practice Question

Which defense-in-depth layer includes measures like access controls, vulnerability management, and intrusion detection systems?

⚠ Common exam trap

The trap here is conflating infrastructure security with operational security — candidates see 'intrusion detection' and pick infrastructure, but the exam expects you to recognize that access control processes, vulnerability management, and IDS monitoring are operational activities, not just infrastructure hardening.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Operational security

Operational security (OpSec) is the defense-in-depth layer focused on day-to-day processes, people, and procedures that protect systems — it explicitly encompasses access controls, vulnerability management, and intrusion detection systems. These are ongoing operational activities rather than physical barriers or data-at-rest protections, which is why OpSec is the correct classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data security

    Why it's wrong here

    Data security is wrong because this layer is concerned with protecting the data itself through encryption, data classification, tokenization, and data loss prevention (DLP) policies. It does not encompass the operational processes of managing user access or continuously monitoring systems. The layer described in the question—access controls and intrusion detection—relies on operational workflows and governance rather than data-centric protections.

  • ✗

    Physical security

    Why it's wrong here

    Physical security is wrong because it addresses threats to the physical environment where systems reside, such as data center access controls, biometric entry systems, and security guards. Logical access management and intrusion detection systems (IDS) operate at the application and network layers, not at the physical perimeter. These technical controls are implemented and maintained by operational security processes, not by physical site protections.

  • ✓

    Operational security

    Why this is correct

    Operational security is correct because it encompasses the day-to-day processes and controls that protect systems, including user access management (authentication, authorization, least privilege), vulnerability management, continuous monitoring, and incident response. These are precisely the measures described in the question—access control lists and intrusion detection—which require ongoing operational discipline rather than static architectural safeguards. This layer ensures that policies and procedures are executed consistently across the environment.

  • ✗

    Infrastructure security

    Why it's wrong here

    Infrastructure security is wrong because this layer covers foundational technology safeguards such as network segmentation, security groups, patch hardening, and platform configuration baselines. While it may include some access controls like firewalls or ACLs at the network level, it is not focused on the broader operational procedures of monitoring and vulnerability management that characterize the operational security layer. The question asks about management and monitoring practices, which belong to operations, not infrastructure design.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.