Question 1
A hospital is redesigning its network to comply with HIPAA regulations, which require stringent protection of Electronic Protected Health Information (ePHI). The security architect has proposed a multi-layered defense strategy. Which of the following sets of controls BEST represents the implementation of a defense-in-depth strategy for protecting ePHI stored on an internal server?
Answer and explanation
Correct answer: D
Defense-in-depth is a strategy that employs multiple layers of security controls to protect assets. The correct option describes four distinct layers: network (segmentation), host (HIDS), data (encryption), and application/user (RBAC). Each of the other options represents only a single layer of security. While valuable, a single control does not constitute a defense-in-depth strategy on its own.