ISC2-CC - Security Principles - Section 1.3

Understand security controls and categorise them as technical, administrative, or physical safeguards.

Classify security controls into the three categories - technical (logical) controls such as firewalls and encryption, administrative (managerial) controls such as policies and training, and physical controls such as locks and guards. Recognise that defence in depth layers controls across all three categories so that no single failure exposes an asset.

Technical controlsAdministrative controlsPhysical controlsDefence in depth

Practice question for this objective

Free sampleSecurity Principleseasy

A study group debates why defence in depth places administrative, technical, and physical controls together in layers. Which statement best captures the rationale for combining the three categories?

  • ACombining categories lets an organisation discard the weakest layer once a stronger layer is proven effective.
  • BIf one control fails or is bypassed, controls from other categories can still detect, deter, or stop the threat. Correct
  • CUsing all three categories guarantees that no attacker can ever breach the protected environment.
  • DLayering the categories chiefly lowers cost by letting one physical control replace all technical controls.
Defence in depth layers administrative, technical, and physical controls so that the failure of one still leaves others protecting the asset. The strategy assumes controls will occasionally fail, so it stacks safeguards of different types; an attacker who defeats one layer still faces independent controls that can detect or block the attack.

Why A is wrong: This misreads the concept: defence in depth retains overlapping layers deliberately rather than removing any once another appears strong.

Why B is correct: Defence in depth assumes any single control may fail, so overlapping layers across categories provide redundancy that keeps protection intact when one layer is defeated.

Why C is wrong: This is tempting but overstated: layering reduces risk and buys time, yet it offers no absolute guarantee against every breach.

Why D is wrong: Cost may improve indirectly, but the categories address different weaknesses and cannot substitute for one another, so this misstates the purpose.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Security Principles objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.