easyMultiple Choice
ISC2 CC Fail-safe defaults / Default deny Practice Question
Network Topology
The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?
⚠ Common exam trap
Watch out — candidates often confuse fail-safe defaults with least privilege, as both involve restricting access, but fail-safe defaults specifically refers to the default deny posture of a policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fail-safe defaults
The default policy in iptables, typically DROP or REJECT for INPUT and FORWARD chains, enforces fail-safe defaults by denying all traffic that is not explicitly allowed. This security principle ensures that only permitted traffic passes, aligning with a deny-by-default posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Fail-safe defaults
Why this is correct
A default DROP policy denies all traffic that no explicit rule permits, so only expressly allowed flows pass. This directly enforces fail-safe defaults: access decisions fall back to denial rather than permission, satisfying the stem's requirement that the default policy itself embody the principle.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple independent controls so one failure does not expose the system. A single default policy statement is one control, not a stack of them; defense in depth would be the right principle where firewalls, segmentation, authentication and monitoring jointly protect the same asset.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits a sensitive task across multiple people so no single actor completes it alone. The default iptables policy simply drops unmatched traffic, which is a deny-by-default stance; separation of duties would be the correct principle where one person cannot both authorise and execute a transaction.
- ✗
Least privilege
Why it's wrong here
Least privilege grants each subject only the permissions its role requires, which the exhibit cannot demonstrate because no user, role or permission assignment is shown. A default DROP policy is a deny-by-default rule; least privilege would be correct where accounts hold excessive rights beyond their duties.
Visual reference
Go deeper
Related to this question
Key term
iptables
iptables is a command-line firewall utility in Linux that uses rules to allow or block network traffic based on packet attributes like source IP, destination port, or protocol.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.