An architecture protects its edge against volumetric attacks, filters traffic between subnets, runs endpoint protection on its virtual machines, validates input in the application, and encrypts data at rest. Why stack all five when each is meant to work on its own?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Defence in depth: each layer slows or contains an attack, so a failure or bypass at one layer does not hand over what sits behind it

Correct. Layers are assumed to fail individually, and the design question at each one is what happens after the layer outside it has already failed.

Not correct Redundancy: if one control goes offline the others take over its function so the system stays available

Wrong — that is availability thinking applied to security. These controls do different jobs at different layers; they are not standby copies of each other.

Not correct Compliance: auditors count controls, so more of them scores better

Wrong, and it inverts cause and effect. Frameworks ask for layered controls because layering demonstrably contains breaches, not the other way round.

Not correct Performance: several cheap checks cost less than one thorough check

Wrong. Layered security generally costs performance rather than saving it, and you accept that cost in exchange for containment.

Why

Defence in depth arranges controls in rings around the thing you actually care about: physical security, identity and access, the perimeter, the network, the compute layer, the application, and data at the centre. Each ring buys time and containment for the ones inside it. That is also why the strongest single control is not a substitute — the design assumes each layer will one day be the one that failed.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services