mediumMultiple Choice
ISC2 CC Practice Question: Deploys firewalls at the network perimeter,…
An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?
⚠ Common exam trap
The trap is confusing defense in depth with diversity of defense — both involve multiple controls, but depth means layering different control types, while diversity means using different products for the same control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
Defense in depth layers multiple independent controls — perimeter firewalls, endpoint antivirus, and encryption at rest — so that if one fails, others still protect the asset. This layered approach is the defining characteristic of defense in depth. The scenario explicitly describes multiple control types at different layers, which matches this principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a single sensitive task across multiple people so no one holds end-to-end control; here one team configures all controls, so no task is divided. It is tempting because layered controls look like distributed responsibility, but it applies to workflow authorisation, such as requiring two approvers for production changes.
- ✗
Diversity of defense
Why it's wrong here
Diversity of defence uses different vendors or mechanisms for the same control layer, whereas firewalls, antivirus and encryption each address separate layers. It is tempting because multiple controls appear varied, but diversity applies when, for example, two different endpoint products guard against one vendor's flaw.
- ✗
Least privilege
Why it's wrong here
Least privilege restricts each identity to the minimum permissions needed, yet the stem describes perimeter, endpoint and data controls, not permission scoping. It is tempting because defence-in-depth controls appear restrictive, but least privilege would be correct when defining IAM role policies or scoping service account access.
- ✓
Defense in depth
Why this is correct
Defense in depth layers independent controls so no single failure exposes the estate. Firewalls filter perimeter traffic, antivirus detects endpoint malware, and encryption protects data at rest if storage is compromised. Each addresses a distinct threat vector, satisfying the stem's requirement for multiple overlapping safeguards rather than reliance on one mechanism.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Defense in depth
Defense in depth is a cybersecurity strategy that uses multiple layers of security controls to protect information and systems, so if one layer fails, another layer is already in place to stop the attack.
Key term
Network perimeter
A network perimeter is the boundary between an organization's internal trusted network and external untrusted networks like the internet, where security controls are deployed to protect internal assets.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.