The correct answer is Applications should be designed to fail closed, defaulting to a secure state. The principle of "defense in failure" (also called "fail secure" or "fail safe") means that when a security mechanism fails or encounters an error, it should default to a secure state that denies access rather than allowing it. This prevents security breaches during exceptional conditions and ensures that security is maintained even when things go wrong.
Applications should collect detailed logs when failures occur is incorrect because while logging failures is an important security practice for detection and forensics, it is a separate principle from defense in failure. Logging documents what happened but doesn't control the security state during failure.
Applications should never fail under any circumstances is incorrect because it represents an unrealistic expectation. All systems will eventually fail under some circumstances, and secure design requires planning for these failures rather than assuming they won't occur.
Applications should hide error details from administrators is incorrect because hiding error details from administrators would hinder troubleshooting and incident response. Proper error handling should hide sensitive details from users while providing administrators with the information needed to address issues.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'fail closed' mean in secure software development?
Open an interactive chat with Bash
Why is logging failures separate from 'defense in failure'?
Open an interactive chat with Bash
How can developers plan for secure failure in applications?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .