Courseiva
hardMultiple Select

ISC2 CC Practice Question: Which THREE of the following are examples of…

Which THREE of the following are examples of implementing defense in depth? (Select THREE.)

⚠ Common exam trap

ISC2 often tests the concept that defense in depth requires multiple independent layers of security, so candidates mistakenly select options that improve convenience (like SSO) or violate security principles (like allowing all traffic) instead of recognizing that each correct option adds a distinct security control at a different layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a firewall to filter traffic

Defense in depth layers multiple independent security controls so that no single failure exposes the whole system. Option B is correct because a firewall filtering traffic enforces a network-perimeter control, inspecting and permitting or denying packets based on rules, which is a classic layered defense. Option D is correct because access control lists (ACLs) restrict which subjects can reach specific resources, adding an authorization layer that limits lateral movement even if perimeter defenses are bypassed. Option E is correct because encrypting data at rest protects confidentiality of stored data, so a breach of storage media or a database does not automatically expose plaintext, forming a data-level control. Option A does not belong: single sign-on centralizes authentication and can actually concentrate risk rather than add a defensive layer. Option C does not belong: allowing all traffic by default is a permissive posture that removes filtering, the opposite of defense in depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enabling single sign-on for all applications

    Why it's wrong here

    Enabling single sign-on centralises authentication but adds no independent layer, so a compromised credential still grants broad access. It is tempting because SSO genuinely improves user convenience and access governance. Defence in depth requires multiple distinct, overlapping controls — network segmentation, patching, least privilege — each of which must be defeated separately.

  • ✓

    Using a firewall to filter traffic

    Why this is correct

    A firewall enforces perimeter filtering of inbound and outbound traffic, forming one independent layer within a defence-in-depth strategy. It satisfies the layered-controls requirement by blocking unauthorised network access before it reaches internal hosts, complementing host, application and data safeguards rather than replacing them.

  • ✗

    Allowing all traffic by default

    Why it's wrong here

    Allowing all traffic by default removes every layer of filtering, so a single compromised host reaches everything — the opposite of defence in depth, which stacks independent controls. It is tempting because permissive defaults reduce troubleshooting and connectivity tickets in trusted, isolated lab or development networks where segmentation and inspection are deliberately absent.

  • ✓

    Implementing access control lists

    Why this is correct

    Access control lists restrict which subjects may reach specific resources, adding an authorisation layer independent of perimeter filtering. This satisfies defence in depth by enforcing granular permit-or-deny decisions at the resource boundary, so a single failed control elsewhere does not expose the protected asset.

  • ✓

    Encrypting data at rest

    Why this is correct

    Encrypting data at rest protects confidentiality even if storage media or backups are stolen, adding a data-layer control independent of network and host defences. This satisfies defence in depth because compromise of one perimeter control does not yield readable data without the cryptographic keys.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.