ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A development team is designing a public-facing API that will handle sensitive customer data. To apply defense in depth, they want security controls that operate at different layers so that a single failure will not expose data. Which approach best meets this goal?
Filter inbound ports with a network firewall, place a web application firewall in front of the API, validate inputs with parameterized queries, and restrict database accounts to least privilege.
Schedule nightly database backups and install an uninterruptible power supply in the data center.
Use autoscaling and a content-delivery network to absorb traffic spikes and improve latency.
Rely solely on prepared statements in the service code and perform quarterly secure code reviews.
Defense in depth relies on complementary controls that sit at multiple points in the stack. Filtering ports with a network firewall addresses the network layer, a web application firewall adds an application-layer shield, input validation through parameterized queries mitigates code-level injection, and database least-privilege ties down the data layer. Together they form layered protection. The other options concentrate on a single layer (code-level reviews), focus mainly on availability rather than security (autoscaling and CDN), or address operational continuity (backups and UPS) without adding distinct security layers, so they do not provide true layered controls against attacks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is defense in depth in cybersecurity?
Open an interactive chat with Bash
What is a web application firewall (WAF), and how does it enhance security?
Open an interactive chat with Bash
Why are parameterized queries important for securing databases?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .