hardMultiple SelectObjective-mapped
SSCP Practice Question: A network security team is implementing a…
A network security team is implementing a defense-in-depth strategy. Which three layers should be included? (Choose three.)
⚠ Common exam trap
The trap here is that candidates often mistake Single Sign-On (SSO) for a security layer because it involves authentication, but it is an access management convenience tool, not a defensive control that protects against network or endpoint threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion Detection System (IDS)
An Intrusion Detection System (IDS) is a key layer in defense-in-depth because it monitors network traffic for suspicious activity and known attack signatures, providing visibility and alerting when perimeter defenses like firewalls are bypassed. It operates by analyzing packets against a rule set (e.g., Snort rules) and generating alerts, enabling a response before damage escalates. This adds a detection layer that complements preventive controls, ensuring that even if an attacker penetrates the outer defenses, the breach is identified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intrusion Detection System (IDS)
Why this is correct
An IDS monitors network traffic for malicious activity, providing a detection layer.
- ✓
Firewall
Why this is correct
A firewall provides network perimeter protection as a prevention layer.
- ✗
Single sign-on (SSO)
Why it's wrong here
SSO simplifies authentication but is not a security layer; it's an access control mechanism.
- ✗
Physical security controls
Why it's wrong here
Physical security is important but is typically considered a separate domain; defense-in-depth often focuses on technical controls.
- ✓
Anti-malware at endpoints
Why this is correct
Endpoint anti-malware provides host-based protection as a prevention and detection layer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.