mediumMultiple Choice
ISC2 CC Practice Question: Ensure that if a server fails, it does not cause…
A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?
⚠ Common exam trap
ISC2 often tests fail-safe by contrasting it with 'fail-open' scenarios, where candidates mistakenly think a failed server should continue operating (e.g., allowing traffic) to maintain availability, but the principle prioritizes security over availability in failure states.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fail-safe
Fail-safe ensures that when a server fails, it defaults to a secure state (e.g., closed ports, denied access) rather than an insecure one. This prevents a security breach by guaranteeing that failure does not inadvertently expose data or allow unauthorized access. In the CC exam, this principle is directly tied to designing systems that remain secure even under fault conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers independent controls so one failure is not fatal, but it does not specify the failure behaviour itself. It suits reducing overall breach likelihood across an estate; the scenario asks how a single failed server should behave, which fail-safe defaults determine.
- ✓
Fail-safe
Why this is correct
Fail-safe design ensures a component failure defaults to a secure, non-compromising state rather than an open one. This satisfies the stem's requirement that server failure must not cause a breach, because the system denies access instead of permitting it when the failure occurs.
- ✗
Default deny
Why it's wrong here
Default deny governs which traffic or actions are permitted, not what happens when a component fails. It is the right principle when defining firewall or authorisation rules, but fail-safe defaults — denying access on failure — address the availability-to-security transition this scenario describes.
- ✗
Least privilege
Why it's wrong here
Least privilege limits each account to the access its role requires, reducing blast radius from compromised credentials. It does not define system behaviour on failure, so it fits designing role assignments, whereas fail-safe defaults govern whether a failed server denies or permits access.
Go deeper
Related to this question
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.