Defense in Depth & Access Control
22 practice questions with explanations — 15 free to try
2 of these 22 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 22 GIAC GSEC (Security Essentials) practice questions on Defense in Depth & Access Control, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Defense in Depth & Access Control: example questions & answers
2 worked examples with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 22-question Defense in Depth & Access Control bank is part of PassNova Premium.
An attacker alters figures in a payroll file without being detected. Which security property has been violated?
- AAvailability
- BIntegrity✓
- CAccountability
- DConfidentiality
Answer: Integrity means data is protected from unauthorised modification, so undetected changes to payroll figures break it. Confidentiality concerns unauthorised disclosure and availability concerns timely access; neither is the primary loss here. Accountability, tracing actions to individuals, may also suffer, but the property directly violated is integrity.
What is the core idea of defence in depth?
- ASeveral independent layers so no single failure exposes the asset✓
- BSpending the whole budget on the single highest risk
- COne very strong perimeter firewall protecting everything
- DRelying on encryption as the only necessary safeguard
Answer: Defence in depth places several independent layers of preventive, detective and corrective controls, across people, process and technology, between a threat and an asset, so the failure or bypass of one layer is caught by another. A single perimeter, a single control type or a budget spent on one risk each creates a single point of failure, which is exactly what layering avoids.