EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium

A new zero-day exploit is discovered targeting a widely used operating system. Before patches are available, security teams are advised to implement intrusion detection systems (IDS) with updated signatures, apply host-based firewalls, and restrict network access to affected services. Which principle of information security is primarily being addressed by these temporary measures?

  1. AIntegrity
  2. BConfidentiality
  3. CAvailability
  4. DDefense in Depth
Show answer & explanation

Correct answer: D. Defense in Depth

Defense in Depth is a strategy that employs multiple layers of security controls to protect against various attack vectors. In this scenario, using IDS, host-based firewalls, and network access restrictions all represent different layers of protection to mitigate a zero-day threat, illustrating this principle.

Why the other options are wrong

  • A. Integrity ensures data is accurate and unaltered, also a goal, but not the strategy of using multiple controls.
  • B. Confidentiality is about protecting data from unauthorized disclosure, which is a goal, but not the principle of layering controls.
  • C. Availability ensures systems and data are accessible when needed, another goal, but not the principle guiding the combined measures.

Defense in Depth

A strategy that employs multiple, overlapping security controls and mechanisms to protect assets. It aims to create a layered security architecture, so if one control fails, others are in place to provide protection.

  • Uses multiple layers of security.
  • Protects against various attack vectors.
  • No single point of failure.
  • Applies to people, technology, and operations.

Memory trick: CIA Triad is the core, but Defense in Depth is the armor.

More Information Security and Ethical Hacking Overview questions