TechNuggets Academy

Defense-in-Depth and Defensible Network Architecture

Free GIAC Security Essentials practice — 6 questions on Defense-in-Depth and Defensible Network Architecture, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Defense-in-Depth and Defensible Network Architecture
A hospital's inline network IPS sits between the core switch and the internet edge, inspecting all traffic to and from a life-safety monitoring system. During a firmware crash, the appliance loses power. The security architect must choose the failure behavior for this device given the organization's priorities. Which configuration is BEST for this defensible network design?
For systems where availability outweighs confidentiality/integrity concerns (life-safety, emergency services), fail-open is the correct choice because losing connectivity could directly endanger patients. GSEC teaches that failure mode selection (fail-open vs. fail-closed) must be driven by the criticality and risk tolerance of the protected asset, not applied uniformly.
Question 2 of 6 · Defense-in-Depth and Defensible Network Architecture
A security engineer needs to capture full-duplex traffic between a core switch and a border router for a new IDS sensor, with zero dropped packets even during oversubscribed traffic bursts, and without the possibility of the monitoring device injecting traffic back onto the wire. Which monitoring approach BEST satisfies these requirements?
A passive network TAP physically replicates full-duplex traffic without relying on switch CPU/backplane resources, so it does not drop packets under load, and passive TAPs are electrically isolated so the monitoring device cannot inject traffic onto the production link — exactly the requirement stated.
Question 3 of 6 · Defense-in-Depth and Defensible Network Architecture
An auditor found that hosts on VLAN 10 (finance) can be reached from VLAN 20 (guest wireless) using a double-tagging (VLAN hopping) technique that exploited the switch's default native VLAN configuration. Which configuration change MOST directly closes this specific attack vector?
Double-tagging VLAN hopping abuses the fact that a frame tagged with the switch's native VLAN gets its outer tag stripped by the first switch, exposing an inner tag for a different VLAN. Assigning an unused, dedicated native VLAN (not VLAN 1 or any production VLAN) and disabling untagged traffic on trunks is the specific, documented mitigation for this attack.
Question 4 of 6 · Defense-in-Depth and Defensible Network Architecture
In defensible network architecture, a 'choke point' is deliberately engineered into the network design. What is the PRIMARY security purpose of a choke point?
A choke point intentionally restricts the number of paths traffic can take so that firewalls, IDS/IPS, and logging can be concentrated at those few points, making enforcement and monitoring consistent and comprehensive — a core defensible-architecture concept.
Question 5 of 6 · Defense-in-Depth and Defensible Network Architecture
A company is redesigning its perimeter to host a public web server, an email relay, and a partner-facing API gateway. The CISO requires that a compromise of any one DMZ host must NOT provide a direct network path to the internal corporate LAN, and that internet-facing and internal-facing filtering rules be enforced by physically or logically separate devices. Which architecture BEST meets these requirements?
A screened subnet (belt-and-suspenders / dual-firewall DMZ) design places independent filtering devices at each boundary, so an attacker who compromises a DMZ host still must bypass a second, separately administered firewall to reach the internal LAN — directly satisfying the 'no direct path' and 'separate enforcement points' requirements.
Question 6 of 6 · Defense-in-Depth and Defensible Network Architecture
A manufacturing company grants third-party maintenance vendors remote access to specific industrial control system (ICS) hosts. Per defense-in-depth principles, the security team wants to ensure vendor connections are restricted to only the required hosts/ports, are separated from the general corporate network, and can be revoked instantly without affecting internal users. Which design BEST achieves this?
A dedicated extranet segment with tightly scoped ACLs enforces least privilege and network segmentation for third parties, isolates vendor risk from internal networks, and allows access to be revoked (by disabling the account/ACL) without touching internal user connectivity — the core defensible-architecture pattern for partner access.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →