A financial services company is developing a new mobile application. The security team has proposed that every user action, including non-transactional views like checking a balance, must be re-authenticated with both a password and a time-based one-time password (TOTP). The product manager argues that this excessive friction will lead users to abandon the app or find insecure workarounds. Which statement BEST represents the security principle the product manager is advocating for in this scenario?
Security mechanisms should be complex enough to demonstrate thorough protection
Security mechanisms should be visibly present to discourage attackers
Security mechanisms should be designed primarily to make users feel protected
Security mechanisms should be transparent enough that they don't unnecessarily impede legitimate users
The correct answer is Security mechanisms should be transparent enough that they don't unnecessarily impede legitimate users. The principle of balancing security with usability recognizes that security controls that are overly burdensome to legitimate users will likely be circumvented, potentially creating new vulnerabilities. Effective security should maintain protection while being as transparent as possible to authorized users. This aligns with the concept of economy of mechanism in security design, which emphasizes simplicity and usability.
Security mechanisms should be visibly present to discourage attackers is incorrect because while security visibility may have deterrent value in some contexts, it often conflicts with usability goals. Highly visible security mechanisms can create friction for legitimate users and don't necessarily improve actual security protection.
Security mechanisms should be designed primarily to make users feel protected is incorrect because the perception of security is less important than actual security effectiveness. Security mechanisms should provide real protection rather than just creating a feeling of safety, which could give users a false sense of security.
Security mechanisms should be complex enough to demonstrate thorough protection is incorrect because complexity typically contradicts good security design principles like economy of mechanism. Complex security mechanisms are generally less user-friendly, more difficult to implement correctly, and more likely to contain vulnerabilities. Effective security should be as simple as possible while achieving protection goals.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of 'economy of mechanism' in security design?
Open an interactive chat with Bash
Why is transparency in security mechanisms important for usability?
Open an interactive chat with Bash
How does complexity in security mechanisms create vulnerabilities?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .