medium
Single Answer
0Which one of the following combinations of controls best embodies the defense-in-depth principle?
Answer Options
A
Encryption of email and network intrusion detection
B
Cloud access security brokers (CASBs) and security awareness training
C
Data loss prevention and multifactor authentication
D
Network firewall and host firewall
Correct Answer: D
Explanation
The defense-in-depth principle suggests using multiple overlapping security controls to achieve the same control objective. Network and host firewalls are both designed to limit network traffic and therefore are an example of defense in depth. The encryption of email and network intrusion detection are unrelated controls and do not satisfy the same objective. The same is true for the combination of CASB and security awareness training and the combination of DLP and multifactor authentication.