ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard

A global enterprise has experienced a significant data breach due to a zero-day vulnerability in a widely used operating system. The incident response team successfully contained and eradicated the threat. During the post-incident review, management emphasizes the need to improve the organization's resilience against future, unknown threats. Which of the following strategies would be MOST effective in achieving this long-term goal?

  1. AEnhancing employee security awareness training on phishing.
  2. BAdopting a 'defense-in-depth' strategy with layered security controls.
  3. CIncreasing the frequency of external penetration testing.
  4. DImplementing a strict patch management policy for all known vulnerabilities.
Show answer & explanation

Correct answer: B. Adopting a 'defense-in-depth' strategy with layered security controls.

While other options are good practices, 'defense-in-depth' is the most comprehensive strategy for improving resilience against *unknown* threats. By implementing multiple, overlapping security controls (e.g., firewalls, IDS/IPS, endpoint protection, network segmentation, strong authentication), a breach of one layer does not automatically compromise the entire system, providing redundancy and making it harder for advanced persistent threats or zero-days to succeed.

Why the other options are wrong

  • A. Employee awareness training is vital for preventing social engineering attacks, but it's a specific control and not a comprehensive strategy for overall system resilience against zero-day technical vulnerabilities.
  • C. Penetration testing is valuable for finding existing weaknesses, but its effectiveness against *unknown* threats is limited to its scope and the testers' knowledge of attack vectors at the time.
  • D. Patch management is crucial for *known* vulnerabilities, but it's less effective against *zero-day* or *unknown* threats.

Defense-in-Depth

Defense-in-depth is a security strategy that employs multiple, overlapping security controls to protect information assets. The failure of one control does not compromise the entire system, providing resilience against various threats, including unknown ones.

  • Uses layered security controls (administrative, technical, physical).
  • Aims to slow down and complicate attacks, not just block them.
  • Improves overall resilience by preventing single points of failure.

Memory trick: Layers of an onion keep threats from the core.

More Security Operations questions