TechKnowSurge
CompTIA Security+ 1.2 CompTIA Security+ 1.1 Cisco CCST Cybersecurity 1.1 ISC2 CC 1.4 CompTIA Security+ 3.2 CompTIA Security+ 3.3 CompTIA Security+ 4.1 CompTIA Security+ 3.1 CompTIA Security+ 2.5 CompTIA Security+ 2.2 CompTIA Security+ 4.6 NIST CSF GV.RR-04
InteractiveSecurityFree

Defense-in-Depth Layer Builder

Place twelve security controls onto the six layers of a defense-in-depth architecture — perimeter, network, endpoint, application, data and human — and read the empty layers as the finding.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: a defense-in-depth diagram has been drawn with six layers and twelve empty positions on it, two per layer, and each position states what a control sitting there has to accomplish. Twelve named controls are on the board. You place each one where it belongs. Why it matters: defense-in-depth is not the claim that more controls are better — it is the assumption that every control eventually fails, turned into a structure that survives the failure. That assumption is what makes the layers the unit of analysis rather than the products. An organization can hold a next-generation firewall, a tuned IPS and a well-run endpoint program and still lose its customer database in an afternoon, if nothing at the data layer meant the copied file was unreadable and nothing at the human layer meant a phished password was insufficient on its own. The layers here run outside in — perimeter, network, endpoint, application, data, human — and the ordering is doing work: an attacker who defeats a layer meets the next one, and an insider who never crossed the perimeter starts at the network layer with everything outside it irrelevant. How to use it: read all twelve positions before placing anything, because the board is built out of pairs that overlap on purpose. A firewall and a web application firewall are both firewalls, and one rules on packets at the network boundary while the other parses HTTP in front of one application, so the word in the name never decides the layer. Full disk encryption and data encryption both encrypt, and one answers a stolen laptop while the other answers a copied file, which is why they sit at different layers and why having one does not give you the other. A VLAN and an ACL are one control split in two — the VLAN draws the boundary and the ACL is what actually enforces it, so segmentation without rules is a diagram rather than a fact about the running network. A WAF and input validation both stop injection, and one is a shield you can raise this afternoon in front of code you cannot change while the other is the repair that makes the vulnerability stop existing. Training and multi-factor authentication are the human layer's pair: one reduces how often somebody is fooled, the other reduces what it costs when they are, and no amount of the first removes the need for the second. Carry the finishing move out of the activity, because it is the one an architect actually performs. Look down a completed stack and remove one control at a time in your head. Where removing a control empties a layer, you have found a gap — and a gap is not compensated by strength elsewhere, because the layers are sequential rather than additive. Nothing at the endpoint layer means the first sign of a compromised workstation is whatever it does loudly enough for another layer to see. Nothing at the data layer means every incident above it is a disclosure rather than an intrusion. Nothing at the human layer means the entire technical stack is bypassed by one convincing email, which is how most real intrusions begin.

What you'll learn

Aligned to

CompTIA Security+
1.2 Summarize fundamental security concepts.
1.1 Compare and contrast various types of security controls.
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
3.3 Compare and contrast concepts and strategies to protect data.
4.1 Given a scenario, apply common security techniques to computing resources.
3.1 Compare and contrast security implications of different architecture models.
2.5 Explain the purpose of mitigation techniques used to secure the enterprise.
2.2 Explain common threat vectors and attack surfaces.
4.6 Given a scenario, implement and maintain identity and access management.
Cisco CCST Cybersecurity
1.1 Define essential security principles
ISC2 CC
1.4 Understand cybersecurity controls
NIST CSF
GV.RR-04 Cybersecurity is included in human resources practices.

Key terms

Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
Virtual LAN
VLAN
A logical grouping of network devices that behave as if they are on the same network regardless of physical location.
Access Control List
ACL
A set of rules that defines which users or systems are granted or denied access to a resource.
Endpoint Detection and Response
EDR
A security solution that continuously monitors endpoint devices to detect, investigate, and respond to threats.
Full Disk Encryption
FDE
Full Disk Encryption is a method of encrypting all data on a storage device at the hardware or software level, ensuring that data remains inaccessible if the device is lost or stolen without the proper authentication credentials or decryption key.
Web Application Firewall
WAF
A firewall that filters and monitors HTTP traffic to and from a web application to prevent attacks.
Input Validation
The process of enforcing rules on user-supplied data to ensure it conforms to expected type, length, format, and content before it is processed by an application.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Intrusion Detection System
IDS
A system that monitors network or system activities for malicious behavior and generates alerts.

Topics

Interactive Build

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →