LOGBOOK

HELP

Quiz Entry - updated: 2026.07.30

Cyber-defence controls group into three layers — prevention, detection, and response. How do measures like network segmentation, XDR monitoring, and an incident-response plan map onto those layers, and where do a SOC and a CSIRT fit?

Prevention stops the attack (segmentation, access management, multi-factor authentication); detection catches what slips through (XDR monitoring, run by the SOC); response contains and recovers (a rehearsed incident-response plan, run by the CSIRT).

Three defensive layers — prevention, then detection by the SOC, then response by the CSIRT.

* Defence in depth — each layer catches what the one before it misses. *

No single layer is enough, so a credible roadmap funds all three:

  • Prevention — raise the bar so most attacks fail: network segmentation to trap a breach in one zone instead of letting it spread, plus user access management and multi-factor authentication / single sign-on so a stolen password alone can't get in.
  • Detection — assume some attacks get through and catch them early: Extended Detection and Response (XDR) with active monitoring across endpoints, cloud, operational technology and servers, watched around the clock by a Security Operations Centre (SOC) — the team whose job is to notice the intrusion.
  • Response — once an incident is confirmed, contain and restore service fast with a rehearsed cybersecurity incident-response plan, executed by the Computer Security Incident Response Team (CSIRT).

WHY all three: prevention is never perfect, so detection shrinks the attacker's dwell time — the months they would otherwise operate unseen — and response turns a would-be catastrophe into a managed event. A roadmap that buys only prevention leaves the organization blind and unable to react when, not if, something slips through. This is also why security is framed as resilience, not just defence: you plan for the breach that lands, not only the ones you block.

From Quiz: ISM / Threat & Impact Modelling | Updated: Jul 30, 2026