Certified Information Systems Security Professional CISSP · Free Practice Question Easy

Question 44

Where would be a good place for us not to implement defense in depth?
  • A Financial Transaction Systems
  • B Non-essential Marketing Web Server
  • C Critical Infrastructure Systems
  • D Customer Personal Data Storage
Reveal correct answer

Correct answer: B

Explanation

The correct answer: Defense in depth is a layered approach to security that utilizes several different controls to protect resources. While this strategy is highly effective, it can also be costly and complex to manage. In non-essential systems, such as a marketing web server which does not contain sensitive or critical data, full implementation of defense in depth may not be the most cost-effective strategy. Resources may be better allocated to protect more critical systems. The incorrect answers: Critical Infrastructure Systems are the most critical systems to the operations of an organization and thus should have the highest level of protection. Defense in depth is a perfect strategy to ensure multiple layers of security controls are in place to protect these systems. Customer Personal Data Storage: Customer data, particularly personal data, is extremely sensitive and needs to be highly protected due to privacy regulations and potential reputational damage if breached. A defense in depth strategy would be highly appropriate for these systems. Financial Transaction Systems: Financial systems are often targeted by cybercriminals and are subject to stringent regulatory controls. It would be beneficial to implement a defense in depth strategy to provide the maximum level of protection.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need