Courseiva
easyMultiple Choice

ISC2 CC Fail-safe defaults / Default deny Practice Question

Network Topology
0 0 ACCEPT alllo * 0.0.0.0/0100 5000 ACCEPT tcp50 2500 DROP tcpRefer to the exhibit.```

The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?

⚠ Common exam trap

Watch out — candidates often confuse fail-safe defaults with least privilege, as both involve restricting access, but fail-safe defaults specifically refers to the default deny posture of a policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fail-safe defaults

The default policy in iptables, typically DROP or REJECT for INPUT and FORWARD chains, enforces fail-safe defaults by denying all traffic that is not explicitly allowed. This security principle ensures that only permitted traffic passes, aligning with a deny-by-default posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fail-safe defaults

    Why this is correct

    A default DROP policy denies all traffic that no explicit rule permits, so only expressly allowed flows pass. This directly enforces fail-safe defaults: access decisions fall back to denial rather than permission, satisfying the stem's requirement that the default policy itself embody the principle.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple independent controls so one failure does not expose the system. A single default policy statement is one control, not a stack of them; defense in depth would be the right principle where firewalls, segmentation, authentication and monitoring jointly protect the same asset.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties splits a sensitive task across multiple people so no single actor completes it alone. The default iptables policy simply drops unmatched traffic, which is a deny-by-default stance; separation of duties would be the correct principle where one person cannot both authorise and execute a transaction.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege grants each subject only the permissions its role requires, which the exhibit cannot demonstrate because no user, role or permission assignment is shown. A default DROP policy is a deny-by-default rule; least privilege would be correct where accounts hold excessive rights beyond their duties.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.