Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

An organization is migrating its on-premises applications to a public cloud environment. The security team is involved from the very beginning of the migration project, ensuring that security requirements are integrated into the architecture design, development, and deployment phases. This approach aims to prevent vulnerabilities rather than fixing them after they occur. Which security concept is being demonstrated?

  1. ASecurity by Obscurity
  2. BDefense in Depth
  3. CZero Trust
  4. DSecure by Design
Show answer & explanation

Correct answer: D. Secure by Design

Secure by Design is a security concept where security is considered and integrated into every stage of the software development lifecycle and system architecture, rather than being an afterthought. The scenario explicitly states security is involved 'from the very beginning' to 'prevent vulnerabilities'.

Why the other options are wrong

  • A. Security by Obscurity relies on hiding system details, which is not a robust security practice and not what's described.
  • B. Defense in Depth involves multiple layers of security controls, not necessarily integrating security into the initial design phase.
  • C. Zero Trust is a model that requires strict identity verification for every person and device trying to access resources, regardless of location, which is a different concept.

Secure by Design

A security concept that advocates for building security into the architecture and design of systems and applications from the very beginning of their lifecycle, rather than adding it on as an afterthought. The goal is to proactively prevent vulnerabilities and minimize attack surfaces.

  • Integrates security from initial design.
  • Proactive, not reactive security.
  • Reduces vulnerabilities and attack surface.
  • Applies throughout the entire lifecycle.

Memory trick: Secure by Design is like building a house with strong walls from the start.

More Security Concepts questions