Which of the following scenarios BEST demonstrates the "fail securely" (fail-safe or fail-closed) design principle when an organization's single sign-on (SSO) authentication service becomes unavailable?
The system authenticates users indefinitely using the last cached valid credential set.
The system denies all login attempts and generates an alert until the SSO service is restored.
The system grants temporary guest access with limited privileges so employees can keep working.
Multi-factor authentication is automatically disabled so users can log in with passwords only.
Denying all login attempts and alerting administrators until the SSO service is restored embodies the fail securely principle. When a critical security control such as authentication fails, the system must default to the most secure state-denying access-rather than falling back to weaker controls, cached credentials, or guest access. This prevents unauthorized entry that could otherwise exploit the failure condition and maintains the confidentiality, integrity, and availability of protected resources.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'fail securely' mean in the context of cybersecurity?
Open an interactive chat with Bash
Why is failing securely preferable to alternatives like guest access or cached credentials?
Open an interactive chat with Bash
What are some examples of systems or scenarios where failing securely is critical?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .