ISC2 Certified in Cybersecurity (CC)Security OperationsHard

A legacy application running on an outdated operating system is critical for business operations but cannot be patched or upgraded due to compatibility issues and vendor support limitations. A recent vulnerability scan has identified several high-severity vulnerabilities on this system. To mitigate the risk, the security team decides to isolate the application within a dedicated network segment, implement strict firewall rules allowing only necessary traffic, and deploy an intrusion detection system (IDS) to monitor for suspicious activity specifically targeting this segment. This strategy is an example of which security control concept?

  1. ALeast privilege
  2. BDefense in depth
  3. CSecure baseline
  4. DSeparation of duties
Show answer & explanation

Correct answer: B. Defense in depth

The strategy involves implementing multiple, layered security controls (network segmentation, strict firewall rules, IDS) around a vulnerable system. This layered approach is the core principle of defense in depth, aiming to provide redundant protection even if one control fails.

Why the other options are wrong

  • A. Least privilege grants only necessary access, which is a specific access control principle, not an overall strategy.
  • C. Secure baseline refers to a minimum security configuration, which is part of configuration management but not the overarching strategy described.
  • D. Separation of duties divides critical tasks among multiple individuals to prevent fraud or error, unrelated here.

Defense in Depth

A cybersecurity strategy that employs multiple layers of security controls (administrative, technical, and physical) to protect information assets, so that if one control fails, others are still in place.

  • Also known as 'layered security'
  • Provides redundancy and resilience
  • Applies to people, technology, and operations

Memory trick: Layers protect like an onion, if one fails, another is there.

More Security Operations questions