A financial application encounters an unexpected error during transaction processing. Which secure design principle should be applied to ensure the system does not default to an insecure state?
'Fail securely' is the correct secure design principle to apply in this scenario. When a system encounters an error or failure condition, it should default to a secure state rather than an insecure one. In practice, this means that when the financial application encounters an unexpected error, it should reject transactions by default rather than accidentally approving them, maintain access restrictions rather than opening them, and preserve security controls even during failure modes.
Other options are incorrect because:
Secure defaults refers to systems being deployed with secure initial configurations.
Defense in depth involves implementing multiple security controls in layers.
Least privilege concerns limiting user access rights to only what's necessary for their job function.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'fail securely' mean in secure system design?
Open an interactive chat with Bash
How does 'secure defaults' differ from 'fail securely'?
Open an interactive chat with Bash
Can 'fail securely' be combined with principles like defense in depth?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .