200-201 exam dumps

200-201 practice question 49 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 49

Select 3

A company wants to improve its cybersecurity posture using a defense-in-depth strategy. The security team decides to implement firewalls, anti-virus software, employee security awareness training, and a process for incident response. Which principles of defense-in-depth are being addressed in this scenario?

  1. A

    Layered security through multiple controls

  2. B

    Relying solely on perimeter defenses

  3. C

    Incorporating human factors into security

  4. D

    Ensuring a single point of failure is avoided

  5. E

    Focusing only on endpoint protection

Show answer and explanation

Correct answers: A, C, D

Explanation

Defense-in-depth is a cybersecurity strategy that employs multiple layers of security controls across technology, processes, and people to protect against a wide range of threats. In this scenario, the company addresses several principles of defense-in-depth, including layered security through multiple controls, incorporating human factors, and preventing a single point of failure by diversifying security measures like firewalls, antivirus, training, and incident response.

  • A. Correct.

    Correct: Layered security through multiple controls is a core aspect of defense-in-depth, and implementing firewalls, anti-virus software, and incident response processes addresses this principle.

  • B. Incorrect.

    Incorrect: Defense-in-depth does not rely solely on perimeter defenses; it involves multiple layers of security across the organization.

  • C. Correct.

    Correct: Incorporating human factors, such as employee security awareness training, is an essential principle of defense-in-depth to address social engineering and insider threats.

  • D. Correct.

    Correct: Ensuring no single point of failure exists is a key principle of defense-in-depth, achieved by diversifying security measures like firewalls and incident response plans.

  • E. Incorrect.

    Incorrect: Focusing only on endpoint protection contradicts the defense-in-depth approach, which emphasizes multiple layers of security.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam