Which statement correctly distinguishes active defense measures from passive defense measures, and which examples illustrate each?

Prepare for the Integrated Defense Test 1 with our comprehensive quiz. Utilize flashcards, multiple-choice questions, and detailed explanations for each answer to ensure you're fully prepared for your exam!

Multiple Choice

Which statement correctly distinguishes active defense measures from passive defense measures, and which examples illustrate each?

Explanation:
Active defense is about reducing risk by design, embedding protections into how a system is built so that even if an attacker breaches outer layers, the impact is limited. Segmentation isolates parts of the network to halt movement, and encryption protects data so it remains unreadable even if accessed. Passive defense, by contrast, focuses on seeing and slowing or stopping attackers as they try to operate—using measures that monitor and respond to activity, such as intrusion prevention systems that can block malicious traffic and deception technologies that mislead and slow down attackers. This pairing fits the idea that proactive, architectural protections aim to minimize risk up front, while detection and disruption measures respond to attacker activity. Other statements stray from that distinction: backups are about recovering from incidents after the fact rather than reducing risk by design, and IDS is a detection tool rather than a primary active defense control. The notion that active defense is for military use or that passive defense is the one that disrupts attackers also misaligns with how these concepts are applied in modern security.

Active defense is about reducing risk by design, embedding protections into how a system is built so that even if an attacker breaches outer layers, the impact is limited. Segmentation isolates parts of the network to halt movement, and encryption protects data so it remains unreadable even if accessed. Passive defense, by contrast, focuses on seeing and slowing or stopping attackers as they try to operate—using measures that monitor and respond to activity, such as intrusion prevention systems that can block malicious traffic and deception technologies that mislead and slow down attackers.

This pairing fits the idea that proactive, architectural protections aim to minimize risk up front, while detection and disruption measures respond to attacker activity. Other statements stray from that distinction: backups are about recovering from incidents after the fact rather than reducing risk by design, and IDS is a detection tool rather than a primary active defense control. The notion that active defense is for military use or that passive defense is the one that disrupts attackers also misaligns with how these concepts are applied in modern security.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy