EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium
A new zero-day exploit is discovered targeting a widely used operating system. Before patches are available, security teams are advised to implement intrusion detection systems (IDS) with updated signatures, apply host-based firewalls, and restrict network access to affected services. Which principle of information security is primarily being addressed by these temporary measures?
- AIntegrity
- BConfidentiality
- CAvailability
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: D. Defense in Depth
Defense in Depth is a strategy that employs multiple layers of security controls to protect against various attack vectors. In this scenario, using IDS, host-based firewalls, and network access restrictions all represent different layers of protection to mitigate a zero-day threat, illustrating this principle.
Why the other options are wrong
- A. Integrity ensures data is accurate and unaltered, also a goal, but not the strategy of using multiple controls.
- B. Confidentiality is about protecting data from unauthorized disclosure, which is a goal, but not the principle of layering controls.
- C. Availability ensures systems and data are accessible when needed, another goal, but not the principle guiding the combined measures.
Defense in Depth
A strategy that employs multiple, overlapping security controls and mechanisms to protect assets. It aims to create a layered security architecture, so if one control fails, others are in place to provide protection.
- Uses multiple layers of security.
- Protects against various attack vectors.
- No single point of failure.
- Applies to people, technology, and operations.
Memory trick: CIA Triad is the core, but Defense in Depth is the armor.