Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A healthcare organization uses a legacy…

A healthcare organization uses a legacy application that stores patient records in plain text. The IT team is planning to upgrade the system but needs to ensure compliance with HIPAA. The new system will be hosted on-premises and accessed by doctors and nurses via a web portal. The security team proposes implementing a VPN for remote access, but the CEO wants to allow access from any device without VPN for convenience. Which principle should guide the decision?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Defense in depth

Defense in depth emphasizes multiple layers of security; a VPN alone is insufficient to protect sensitive health records. The CEO's request sacrifices security for convenience, and risk acceptance is not the best approach when stronger controls are feasible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why this is correct

    Defense in depth emphasizes multiple layers; a VPN alone is insufficient.

  • Least privilege

    Why it's wrong here

    Least privilege addresses access permissions, not the overall security architecture.

  • Security is an enabler

    Why it's wrong here

    Security is an enabler supports business, but not the primary guide here.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is not the best approach when stronger controls are feasible.

About these practice questions

This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?

medium
  • A.Defense in depth
  • B.Separation of duties
  • C.Least privilege
  • D.Need-to-know

Why A: Defense in depth is the correct principle because it involves implementing multiple layers of security controls (firewalls, IDS, ACLs) to protect assets, ensuring that if one layer fails, others still provide protection. Separation of duties (B) divides tasks among multiple people to prevent fraud, least privilege (C) limits access rights to only what is necessary, and need-to-know (D) restricts access to information required for job functions—none of these directly address the use of multiple security layers.

Variation 2. A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?

medium
  • A.Fail-safe
  • B.Least privilege
  • C.Need to know
  • D.Defense in depth

Why D: Defense in depth is the correct principle because it involves implementing multiple layers of security controls so that if one authentication factor is compromised, other layers still protect the system. In this scenario, requiring multiple authentication factors (e.g., password plus biometric or token) ensures that a single compromised factor does not grant full access, maintaining overall system security.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.