Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security administrator is explaining the concept of defense in depth to a new team member. Which statement best describes this approach?

⚠ Common exam trap

Many exam-takers confuse defense in depth with a single strong control (like a firewall or encryption), failing to recognize that the core principle is layering multiple independent controls to provide redundancy and depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Layering multiple security controls across different areas of the IT environment

Defense in depth is a cybersecurity strategy that employs multiple layers of security controls across different areas of the IT environment (network, endpoint, application, data, and physical). This approach ensures that if one control fails, another is already in place to mitigate the threat, providing redundancy and reducing the risk of a single point of failure. Microsoft's security framework, including tools like Microsoft Defender for Cloud and Azure Firewall, operationalizes this concept by integrating protections at each layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Using a single, strong firewall to block all external traffic

    Why it's wrong here

    Using a single, strong firewall to block all external traffic, while a crucial component of network security, represents a single point of failure and is inadequate for a defense-in-depth strategy. Even the most advanced firewall cannot protect against internal threats, zero-day exploits, sophisticated phishing attacks that bypass perimeter defenses, or misconfigurations within the network. A true layered defense requires multiple, overlapping network controls, such as intrusion detection/prevention systems, network segmentation, and endpoint protection, to provide resilience against diverse attack vectors.

    When this WOULD be correct

    If the question asked for a simple, cost-effective security approach for a small network with minimal threats, a single strong firewall might be considered sufficient.

  • Layering multiple security controls across different areas of the IT environment

    Why this is correct

    Defense in depth fundamentally involves deploying a comprehensive array of security controls across various layers and domains within an IT environment. This layered strategy ensures that if one security control is compromised or bypassed, other independent controls are still in place to detect, prevent, or mitigate the attack. It encompasses physical, technical, and administrative safeguards, creating a resilient security posture that significantly increases the effort and resources required for an attacker to succeed.

  • Relying solely on encryption to protect all data at rest and in transit

    Why it's wrong here

    Relying exclusively on encryption, whether for data at rest or in transit, provides robust confidentiality but is insufficient for a complete security strategy. While encryption is a critical technical control, it does not address other vital security aspects such as unauthorized access to systems, insider threats, or the availability and integrity of data and services. A holistic defense-in-depth approach requires additional layers like access controls, network segmentation, vulnerability management, and security monitoring to protect against a broader spectrum of threats.

    When this WOULD be correct

    In a question asking 'Which control best protects data confidentiality during transmission?', encryption (e.g., TLS) would be the correct answer, as it specifically secures data in transit.

  • Implementing only physical security measures to protect the data center

    Why it's wrong here

    Implementing solely physical security measures, such as locks, guards, and surveillance for a data center, creates a strong perimeter but leaves the internal logical environment vulnerable. Physical security is an essential foundational layer, yet it does not protect against cyberattacks, software vulnerabilities, logical access breaches, or data exfiltration once an attacker has bypassed the physical boundary or gained remote access. A comprehensive defense-in-depth strategy mandates additional layers including network security, application security, data security, and robust administrative controls.

    When this WOULD be correct

    A question asking for the primary security control for a data center's perimeter, such as 'Which measure best prevents unauthorized physical access to a server room?' would make physical security the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Layering multiple security controls across different areas of the IT environmentCorrect answer

Why this is correct

Defense in depth fundamentally involves deploying a comprehensive array of security controls across various layers and domains within an IT environment. This layered strategy ensures that if one security control is compromised or bypassed, other independent controls are still in place to detect, prevent, or mitigate the attack. It encompasses physical, technical, and administrative safeguards, creating a resilient security posture that significantly increases the effort and resources required for an attacker to succeed.

Using a single, strong firewall to block all external trafficWrong answer — click to see why

Why this is wrong here

Defense in depth requires multiple layers of security, not a single firewall. A single firewall can be bypassed or fail, leaving the environment unprotected.

★ When this WOULD be the correct answer

If the question asked for a simple, cost-effective security approach for a small network with minimal threats, a single strong firewall might be considered sufficient.

Why candidates choose this

Candidates may think a strong firewall is a comprehensive solution, overlooking the need for layered defenses against diverse attack vectors.

Relying solely on encryption to protect all data at rest and in transitWrong answer — click to see why

Why this is wrong here

Defense in depth requires multiple layers of security, not a single control. Relying solely on encryption ignores other critical layers like network segmentation, access controls, and monitoring.

★ When this WOULD be the correct answer

In a question asking 'Which control best protects data confidentiality during transmission?', encryption (e.g., TLS) would be the correct answer, as it specifically secures data in transit.

Why candidates choose this

Candidates may overvalue encryption as a comprehensive security measure, mistakenly believing it alone can address all threats, rather than understanding it is just one layer in a defense-in-depth strategy.

Implementing only physical security measures to protect the data centerWrong answer — click to see why

Why this is wrong here

Defense in depth requires multiple layers of security, not just physical measures. Relying solely on physical security ignores network, application, and data security, leaving many attack vectors unprotected.

★ When this WOULD be the correct answer

A question asking for the primary security control for a data center's perimeter, such as 'Which measure best prevents unauthorized physical access to a server room?' would make physical security the correct answer.

Why candidates choose this

Candidates may think physical security is the foundation of all security and overlook the need for layered controls, especially if they focus on the data center aspect of the scenario.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.