hardMultiple Select
ISC2 CC Practice Question: Which THREE of the following are examples of…
Which THREE of the following are examples of implementing defense in depth? (Select THREE.)
⚠ Common exam trap
ISC2 often tests the concept that defense in depth requires multiple independent layers of security, so candidates mistakenly select options that improve convenience (like SSO) or violate security principles (like allowing all traffic) instead of recognizing that each correct option adds a distinct security control at a different layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a firewall to filter traffic
Defense in depth layers multiple independent security controls so that no single failure exposes the whole system. Option B is correct because a firewall filtering traffic enforces a network-perimeter control, inspecting and permitting or denying packets based on rules, which is a classic layered defense. Option D is correct because access control lists (ACLs) restrict which subjects can reach specific resources, adding an authorization layer that limits lateral movement even if perimeter defenses are bypassed. Option E is correct because encrypting data at rest protects confidentiality of stored data, so a breach of storage media or a database does not automatically expose plaintext, forming a data-level control. Option A does not belong: single sign-on centralizes authentication and can actually concentrate risk rather than add a defensive layer. Option C does not belong: allowing all traffic by default is a permissive posture that removes filtering, the opposite of defense in depth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling single sign-on for all applications
Why it's wrong here
Enabling single sign-on centralises authentication but adds no independent layer, so a compromised credential still grants broad access. It is tempting because SSO genuinely improves user convenience and access governance. Defence in depth requires multiple distinct, overlapping controls — network segmentation, patching, least privilege — each of which must be defeated separately.
- ✓
Using a firewall to filter traffic
Why this is correct
A firewall enforces perimeter filtering of inbound and outbound traffic, forming one independent layer within a defence-in-depth strategy. It satisfies the layered-controls requirement by blocking unauthorised network access before it reaches internal hosts, complementing host, application and data safeguards rather than replacing them.
- ✗
Allowing all traffic by default
Why it's wrong here
Allowing all traffic by default removes every layer of filtering, so a single compromised host reaches everything — the opposite of defence in depth, which stacks independent controls. It is tempting because permissive defaults reduce troubleshooting and connectivity tickets in trusted, isolated lab or development networks where segmentation and inspection are deliberately absent.
- ✓
Implementing access control lists
Why this is correct
Access control lists restrict which subjects may reach specific resources, adding an authorisation layer independent of perimeter filtering. This satisfies defence in depth by enforcing granular permit-or-deny decisions at the resource boundary, so a single failed control elsewhere does not expose the protected asset.
- ✓
Encrypting data at rest
Why this is correct
Encrypting data at rest protects confidentiality even if storage media or backups are stolen, adding a data-layer control independent of network and host defences. This satisfies defence in depth because compromise of one perimeter control does not yield readable data without the cryptographic keys.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.