Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An organization is hosting a multi-tier web application in Azure that processes sensitive customer records. To protect the environment against security breaches, the cloud architect deploys edge protection with a Web Application Firewall (WAF), configures Network Security Groups for virtual networks, enforces strict identity controls with Multi-Factor Authentication (MFA), and enables data encryption at rest.
What is the primary benefit of implementing this defense-in-depth strategy?
It provides multiple coordinated security layers so that if a single control is compromised, subsequent layers prevent unauthorized access.
It guarantees absolute immunity from cyberattacks and removes the necessity to monitor telemetry logs.
It consolidates all cloud resources into a single broad network perimeter to minimize latency and management overhead.
It replaces identity and access management controls with network-level packet filtering across all workloads.
It provides multiple coordinated security layers so that if a single control is compromised, subsequent layers prevent unauthorized access.
Defense-in-depth is a comprehensive cybersecurity strategy that employs a series of layered defense mechanisms to protect sensitive data and infrastructure. Rather than relying on a single defensive boundary, defense-in-depth creates multiple independent levels of security across physical, identity, perimeter, network, compute, application, and data layers.
The primary objective of a defense-in-depth model is to slow down or halt attackers who attempt to gain unauthorized access to an environment. If an adversary manages to bypass or compromise an outer layer—such as exploiting a vulnerability in a public web endpoint—the remaining interior controls (such as network segmentation, role-based access control, and data encryption) continue to restrict lateral movement and prevent unauthorized data exfiltration.
Modern cloud architectures cannot depend solely on perimeter firewalls. Adopting a layered defense ensures that each component assumes potential breach conditions and independently validates and protects assets, maximizing overall cloud workload safety.
It guarantees absolute immunity from cyberattacks and removes the necessity to monitor telemetry logs.
It consolidates all cloud resources into a single broad network perimeter to minimize latency and management overhead.
It replaces identity and access management controls with network-level packet filtering across all workloads.