Courseiva
mediumMultiple SelectObjective-mapped

CISSP Practice Question: Which TWO principles are fundamental to a…

Which TWO principles are fundamental to a defense-in-depth security architecture?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Diversity of defense

Options A and D are correct: Defense in depth relies on layered security controls (D) and diversity of defense (A) to ensure that if one layer fails, others still protect. Option B (centralized logging) is a good practice but not a fundamental principle of defense in depth. Option C (single point of failure) is the opposite of what defense in depth aims to avoid. Option E (minimal user training) is counterproductive to security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Diversity of defense

    Why this is correct

    Diversity of defense is a fundamental principle requiring the deployment of different types of security controls, technologies, and vendors across various layers. This strategic heterogeneity ensures that a single vulnerability or attack method targeting one specific control type cannot bypass all defenses simultaneously. By avoiding reliance on a uniform set of protections, the overall resilience against sophisticated threats is significantly enhanced, making it harder for attackers to find a common weakness.

  • Centralized logging

    Why it's wrong here

    While crucial for effective security monitoring, incident response, and forensic analysis, centralized logging is an operational mechanism rather than a core principle of defense in depth itself. Defense in depth focuses on the strategic layering and placement of preventative and detective controls, whereas logging is a function that collects and aggregates data *from* these controls. It provides visibility into security events but does not inherently constitute a layer of defense.

  • Single point of failure

    Why it's wrong here

    Defense in depth fundamentally aims to eliminate or significantly mitigate single points of failure within an organization's security posture. By implementing multiple, independent layers of controls, the strategy ensures that the compromise or failure of one specific security mechanism does not lead to a complete system breach. Therefore, embracing or allowing a single point of failure directly contradicts the core objective of creating robust, redundant protection.

  • Layered security controls

    Why this is correct

    Layered security controls represent the foundational concept of defense in depth, involving the strategic deployment of multiple, independent security mechanisms in a series. Each successive layer acts as a distinct barrier, requiring an attacker to overcome numerous defenses to reach the protected asset. This multi-tiered approach significantly increases the complexity, time, and resources necessary for a successful breach, thereby enhancing overall security resilience.

  • Minimal user training

    Why it's wrong here

    Minimal user training is antithetical to a strong defense-in-depth strategy, as the human element remains a critical component of an organization's security posture. Effective security awareness training empowers users to recognize and resist social engineering, phishing, and other human-centric attacks, acting as an essential administrative control. Neglecting this aspect creates significant vulnerabilities that can bypass even robust technical and physical controls, undermining the entire security framework.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.