Courseiva
hardMultiple SelectObjective-mapped

SSCP Practice Question: A network security team is implementing a…

A network security team is implementing a defense-in-depth strategy. Which three layers should be included? (Choose three.)

⚠ Common exam trap

The trap here is that candidates often mistake Single Sign-On (SSO) for a security layer because it involves authentication, but it is an access management convenience tool, not a defensive control that protects against network or endpoint threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Intrusion Detection System (IDS)

An Intrusion Detection System (IDS) is a key layer in defense-in-depth because it monitors network traffic for suspicious activity and known attack signatures, providing visibility and alerting when perimeter defenses like firewalls are bypassed. It operates by analyzing packets against a rule set (e.g., Snort rules) and generating alerts, enabling a response before damage escalates. This adds a detection layer that complements preventive controls, ensuring that even if an attacker penetrates the outer defenses, the breach is identified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Intrusion Detection System (IDS)

    Why this is correct

    An IDS monitors network traffic for malicious activity, providing a detection layer.

  • Firewall

    Why this is correct

    A firewall provides network perimeter protection as a prevention layer.

  • Single sign-on (SSO)

    Why it's wrong here

    SSO simplifies authentication but is not a security layer; it's an access control mechanism.

  • Physical security controls

    Why it's wrong here

    Physical security is important but is typically considered a separate domain; defense-in-depth often focuses on technical controls.

  • Anti-malware at endpoints

    Why this is correct

    Endpoint anti-malware provides host-based protection as a prevention and detection layer.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.