Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 50
By implementing a layered defense strategy across our organization, what do we improve?
-
A
We improve our compliance with industry regulations
-
B
We improve our network performance
-
C
We improve our overall security posture
-
D
We improve our ability to respond to cyber threats
Reveal correct answer
Correct answer: C
Explanation
The correct answer: We improve our overall security posture: A layered defense strategy, also known as defense in depth, involves using multiple layers of security controls (preventative, detective, and reactive) across an organization. This strategy not only helps to prevent security breaches, but also reduces the impact should a breach occur. The concept behind layered defense is not to rely on a single security measure, but to deploy a series of different types of controls that complement each other. This comprehensive approach effectively enhances an organization's overall security posture, making it much more difficult for malicious actors to penetrate or cause damage. The incorrect answers: We improve our ability to respond to cyber threats: While a layered defense strategy does enhance the organization's resilience against cyber threats, it does not directly improve the ability to respond to them. Response capabilities largely depend on the incident response plan, the trained personnel, and the specific tools designed for incident detection, analysis, and remediation. Layered defense is more focused on prevention and minimization of breaches. We improve our network performance: A layered defense strategy doesn't necessarily improve network performance. In fact, the introduction of additional security layers can sometimes impact performance due to the extra processing required for security checks and monitoring. The trade-off between security and performance is often deemed worthwhile in order to protect the organization's assets. We improve our compliance with industry regulations: While a layered defense strategy can help meet certain security requirements specified by industry regulations, it does not directly lead to improved compliance. Compliance involves a broad set of activities including policy definition, risk assessments, training, audit and assurance activities, etc. Although a robust security infrastructure could support compliance efforts, the layered defense strategy alone isn't enough to ensure full compliance with industry regulations.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
