LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

Security by obscurity failed as computers spread. Which three reactions to that failure define everything that came after?

(a) access control via the network — perimeter security; (b) access control via authentication and authorisation — AAA; (c) measures on the system itself — hardening. Everything later is a refinement or a combination of these three.

The three reactions to the failure of obscurity

* Three answers to one question, each attacking it at a different point — and everything later is a refinement of them. *

They are worth learning as a set, because they are three different answers to the same problem — "how do I keep bad actors and bad actions away from my system?" — each attacking it at a different point:

Reaction Where control happens The question it answers Where it led
(a) Perimeter The network path to the system Where is this coming from? Firewalls → smart security tools → macro-perimeter → micro-perimeter
(b) AAA The identity of the actor Who is this, and what may they do? Passwords → MFA/SSO → IAM → risk-based access / zero trust
(c) On the system The target system itself Can the system withstand this request? Patching, hardening, minimalism, application-level controls

Two observations make the table useful rather than merely tidy:

  • None of the three is sufficient alone, and each one's weakness is roughly another's strength. The network cannot tell you who is typing; the identity cannot tell you whether the system it is reaching is patched; hardening cannot tell you whether this connection should exist at all.
  • They accumulate rather than replace. Perimeter security did not remove obscurity, AAA did not remove firewalls, and zero trust did not remove hardening. That is precisely why the estate you inherit contains all of them at different levels of maintenance — and why the eventual answer is combination, not selection.

Tip: when you meet an unfamiliar security design, first ask which of the three it is doing. It is rarely more than two, and the missing one is usually the finding.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026