Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: Deploys firewalls at the network perimeter,…

An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?

⚠ Common exam trap

The trap is confusing defense in depth with diversity of defense — both involve multiple controls, but depth means layering different control types, while diversity means using different products for the same control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in depth

Defense in depth layers multiple independent controls — perimeter firewalls, endpoint antivirus, and encryption at rest — so that if one fails, others still protect the asset. This layered approach is the defining characteristic of defense in depth. The scenario explicitly describes multiple control types at different layers, which matches this principle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a single sensitive task across multiple people so no one holds end-to-end control; here one team configures all controls, so no task is divided. It is tempting because layered controls look like distributed responsibility, but it applies to workflow authorisation, such as requiring two approvers for production changes.

  • ✗

    Diversity of defense

    Why it's wrong here

    Diversity of defence uses different vendors or mechanisms for the same control layer, whereas firewalls, antivirus and encryption each address separate layers. It is tempting because multiple controls appear varied, but diversity applies when, for example, two different endpoint products guard against one vendor's flaw.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege restricts each identity to the minimum permissions needed, yet the stem describes perimeter, endpoint and data controls, not permission scoping. It is tempting because defence-in-depth controls appear restrictive, but least privilege would be correct when defining IAM role policies or scoping service account access.

  • ✓

    Defense in depth

    Why this is correct

    Defense in depth layers independent controls so no single failure exposes the estate. Firewalls filter perimeter traffic, antivirus detects endpoint malware, and encryption protects data at rest if storage is compromised. Each addresses a distinct threat vector, satisfying the stem's requirement for multiple overlapping safeguards rather than reliance on one mechanism.

Go deeper

Related to this question

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.