Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank applies a defence-in-depth approach to protect a customer database. Which combination best illustrates multiple, independent layers of control?

Network segmentation, encryption of data at rest, and strong authentication with activity monitoring best show defence in depth. They are diverse and independent layers, so failure of one does not expose the database. The other options rely on one control or share a common point of failure.

  1. ANetwork segmentation, encryption of data at rest, and strong authentication with activity monitoringCorrect
  2. BThree different firewalls from one vendor all managed by one administrator with a shared password
  3. CAnnual staff cyber awareness training only
  4. DA single, highly advanced perimeter firewall

Explanation

Defence in depth uses diverse, complementary controls at different levels so one failure does not expose the asset. Segmentation, encryption and authentication with monitoring are independent layers. Multiple firewalls with a shared credential share a single point of failure, and single-control options give no layering.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions