Prepare for the Trusted Agent Exam with engaging questions, flashcards, and detailed explanations. Dive deep into essential topics to increase your chances of success. Ace your exam with confidence!

Multiple Choice

Which control approach best supports defense in depth?

Defense in depth is about implementing multiple, overlapping controls across people, processes, and technology so that no single failure leads to a breach. This layered approach reduces reliance on any one defense and provides multiple opportunities to detect, block, and respond to threats at different points in the attack chain. When controls cover people (security awareness, least privilege, access controls), processes (change management, incident response, policy enforcement), and technology (antivirus, firewalls, encryption, logging and monitoring), they complement each other and create redundancy that makes success much harder for an attacker. That’s why a multi-layer approach is the strongest defense. Relying on a single antivirus misses other vectors; training alone doesn’t stop technical exploits or misconfigurations; and disabling logging removes visibility needed to detect and investigate incidents.

Defense in depth is about implementing multiple, overlapping controls across people, processes, and technology so that no single failure leads to a breach. This layered approach reduces reliance on any one defense and provides multiple opportunities to detect, block, and respond to threats at different points in the attack chain. When controls cover people (security awareness, least privilege, access controls), processes (change management, incident response, policy enforcement), and technology (antivirus, firewalls, encryption, logging and monitoring), they complement each other and create redundancy that makes success much harder for an attacker. That’s why a multi-layer approach is the strongest defense. Relying on a single antivirus misses other vectors; training alone doesn’t stop technical exploits or misconfigurations; and disabling logging removes visibility needed to detect and investigate incidents.