Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 44
Where would be a good place for us not to implement defense in depth?
- A Financial Transaction Systems
- B Non-essential Marketing Web Server
- C Critical Infrastructure Systems
- D Customer Personal Data Storage
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Defense in depth is a layered approach to security that utilizes several different controls to protect resources. While this strategy is highly effective, it can also be costly and complex to manage. In non-essential systems, such as a marketing web server which does not contain sensitive or critical data, full implementation of defense in depth may not be the most cost-effective strategy. Resources may be better allocated to protect more critical systems. The incorrect answers: Critical Infrastructure Systems are the most critical systems to the operations of an organization and thus should have the highest level of protection. Defense in depth is a perfect strategy to ensure multiple layers of security controls are in place to protect these systems. Customer Personal Data Storage: Customer data, particularly personal data, is extremely sensitive and needs to be highly protected due to privacy regulations and potential reputational damage if breached. A defense in depth strategy would be highly appropriate for these systems. Financial Transaction Systems: Financial systems are often targeted by cybercriminals and are subject to stringent regulatory controls. It would be beneficial to implement a defense in depth strategy to provide the maximum level of protection.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
