mediumMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: A healthcare organization uses a legacy…
A healthcare organization uses a legacy application that stores patient records in plain text. The IT team is planning to upgrade the system but needs to ensure compliance with HIPAA. The new system will be hosted on-premises and accessed by doctors and nurses via a web portal. The security team proposes implementing a VPN for remote access, but the CEO wants to allow access from any device without VPN for convenience. Which principle should guide the decision?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
Defense in depth emphasizes multiple layers of security; a VPN alone is insufficient to protect sensitive health records. The CEO's request sacrifices security for convenience, and risk acceptance is not the best approach when stronger controls are feasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defense in depth
Why this is correct
Defense in depth emphasizes multiple layers; a VPN alone is insufficient.
- ✗
Least privilege
Why it's wrong here
Least privilege addresses access permissions, not the overall security architecture.
- ✗
Security is an enabler
Why it's wrong here
Security is an enabler supports business, but not the primary guide here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is not the best approach when stronger controls are feasible.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
About these practice questions
This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?
medium- ✓ A.Defense in depth
- B.Separation of duties
- C.Least privilege
- D.Need-to-know
Why A: Defense in depth is the correct principle because it involves implementing multiple layers of security controls (firewalls, IDS, ACLs) to protect assets, ensuring that if one layer fails, others still provide protection. Separation of duties (B) divides tasks among multiple people to prevent fraud, least privilege (C) limits access rights to only what is necessary, and need-to-know (D) restricts access to information required for job functions—none of these directly address the use of multiple security layers.
Variation 2. A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?
medium- A.Fail-safe
- B.Least privilege
- C.Need to know
- ✓ D.Defense in depth
Why D: Defense in depth is the correct principle because it involves implementing multiple layers of security controls so that if one authentication factor is compromised, other layers still protect the system. In this scenario, requiring multiple authentication factors (e.g., password plus biometric or token) ensures that a single compromised factor does not grant full access, maintaining overall system security.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.