Which statement best reflects the principle of fail-safe defaults?

Get ready for your WGU ITEC2034 D385 Software Security and Testing Test. Study with multiple choice questions that include hints and explanations. Boost your confidence for your exam day!

Multiple Choice

Which statement best reflects the principle of fail-safe defaults?

Explanation:
Fail-safe defaults means designing the system so it starts in a secure state and denies access unless there is an explicit permission. In practice this is a deny-by-default approach: access is not granted unless a policy or rule specifically allows it. This minimizes privileges by default and reduces the chances of accidental exposure or exploitation, because every access requires explicit authorization. That idea is why the statement saying systems should default to a secure state and deny access unless explicitly allowed best captures fail-safe defaults. The other options describe opposite or insecure practices—granting access unless blocked, using default credentials, or avoiding audits—which do not align with this principle.

Fail-safe defaults means designing the system so it starts in a secure state and denies access unless there is an explicit permission. In practice this is a deny-by-default approach: access is not granted unless a policy or rule specifically allows it. This minimizes privileges by default and reduces the chances of accidental exposure or exploitation, because every access requires explicit authorization.

That idea is why the statement saying systems should default to a secure state and deny access unless explicitly allowed best captures fail-safe defaults. The other options describe opposite or insecure practices—granting access unless blocked, using default credentials, or avoiding audits—which do not align with this principle.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy