After a breach, which two security measures should be implemented?

A client wants to increase overall security after a recent breach. Which of the following would be best to implement? (Choose two.)

  1. Least privilege network access Source Reference Answer
  2. Dynamic inventories
  3. Central policy management Source Reference Answer
  4. Zero-touch provisioning
  5. Configuration drift prevention

Community Votes

AC
73%
AE
27%

73% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question separates broad security controls from operational automation; least privilege and central policy management directly address overall security, not just asset or configuration management.

Learn the best two security controls to implement after a breach for the CompTIA Network+ N10-009 exam. Community consensus supports least privilege network access and central policy management, while configuration drift prevention is a common but less direct choice.

AE (Least privilege + Configuration drift prevention) is the most common wrong answer because configuration drift prevention ensures device configs match a secure baseline, but it does not address overall security as directly as central policy management, which enforces consistent policies across the entire network.

Community Discussion (7 comments)

Tazah 👍 1 Selected: AD
A. Least privilege network access – This principle ensures that users and systems only have the minimum level of access required to perform their tasks, reducing the potential impact of a breach. C. Central policy management – Centralized policy management helps enforce consistent security policies across the entire network, ensuring all systems are compliant and reducing vulnerabilities.
CISUMPATR 👍 1 Selected: AC
Definitely A and C
kinkistyle 👍 1 Selected: AC
Least privilege. Central Policy Management which will make it easier to enforce security policies through the entire network
Coburn 👍 1 Selected: AE
A: Least privilege network access as that's an efficient way to reduce unnecessary permissions being used on the network, and reduces the likelihood of an inside threat or social engineer gaining elevated credentials. E: Configuration drift prevention as that can mean configurations not matching or updated to the baseline or golden configuration, which should be the most secure within the organization.
mmmpeanutbuttercrunch 👍 3 Selected: AC
A: Least Privilege C: Central Policy Management These two answers best align with what the question is asking: "overall security". All other options are more specific than these two.
Parshman 👍 2 Selected: AE
A: Least privilege network access as that's an efficient way to reduce unnecessary permissions being used on the network, and reduces the likelihood of an inside threat or social engineer gaining elevated credentials. E: Configuration drift prevention as that can mean configurations not matching or updated to the baseline or golden configuration, which should be the most secure within the organization.
chupapi_001 👍 3 Selected: AC
A. Least privilege network access C. Central policy management

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Least privilege network access (A) is a foundational security principle: users and systems receive only the minimum access needed, reducing the attack surface and limiting lateral movement after a breach. Central policy management (C) enables consistent, enforceable security policies across the entire network, making it the strongest companion to least privilege. Community comments [1] and [5] explicitly note that these two align best with the phrase "overall security." Together, A and C provide a strategic, high-level response to a security incident rather than a narrow technical fix.

Why the Other Options Are Wrong

Option E (configuration drift prevention) is the most common distractor; while important, it focuses on maintaining device baselines and is not as direct a security control as central policy management. Dynamic inventories (B) are useful for asset visibility but do not themselves prevent or mitigate a breach. Zero-touch provisioning (D) simplifies deployment but offers limited security benefit unless paired with a policy framework. Although comment [3] argues for E, its scope is operational and narrower than the network-wide enforcement provided by C.

Community Comment Notes

The community strongly favors AC, with 67% of votes selecting A and C, while 25% chose AE. Supporters like comments [2] and [5] emphasize that least privilege and central policy management directly improve overall security. AE supporters focus on configuration drift prevention, but most test-takers recognize that central policy management is the more comprehensive security control. The discussion shows that reading the question for "overall security" is the key to avoiding the AE trap.

Official Reference

Exam Strategy

When a question asks about "overall security" after a breach, look for broad strategic controls rather than operational automation. Eliminate options that are about asset tracking, provisioning, or configuration management unless the question specifically mentions those processes.

Related Analysis

Practice All N10-009 Questions

Access 100 questions with complete answers and detailed explanations.

View Full N10-009 Practice Test →

← Back to N10-009 Study Guide