Courseiva
mediumMultiple Select

ISC2 CC Practice Question: Which TWO of the following are fundamental…

Which TWO of the following are fundamental security principles? (Select TWO.)

⚠ Common exam trap

ISC2 often tests the distinction between security principles (like defense in depth and least privilege) and design concepts (like fail-open or complexity), so candidates mistakenly select 'fail-open' because it sounds security-related, but it actually reduces security in a failure scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defense in depth

Defense in depth (C) is a fundamental security principle because it layers multiple independent controls (network, host, application, data) so that if one control fails, others still protect the asset. Least privilege (D) is also fundamental: users, processes, and services should be granted only the minimum access rights needed to perform their function, limiting the blast radius of compromise or misuse. The other options are not fundamental security principles: fail-open (A) is an availability-oriented failure mode that weakens security by allowing access when a control fails, need to share (B) is the opposite of the need-to-know principle, and complexity (E) is a known enemy of security that increases attack surface and misconfiguration risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fail-open

    Why it's wrong here

    Fail-open lets a control default to permitting access when it malfunctions, so availability is preserved at the cost of enforcement; fundamental principles instead include fail-safe defaults and least privilege. It is tempting because fail-open suits life-safety or availability-critical systems where outage harm exceeds exposure.

  • ✗

    Need to share

    Why it's wrong here

    Need to share inverts the least-privilege and need-to-know principles, granting broad access by default rather than restricting it to justified recipients. It is tempting because collaboration and data availability genuinely require sharing, so the principle applies to business workflows, not to security design.

  • ✓

    Defense in depth

    Why this is correct

    Defense in depth is a fundamental security principle: it layers independent controls so failure of one does not expose the whole system. This satisfies the stem's requirement to select genuine fundamental principles, distinguishing it from specific technologies or implementation tactics.

  • ✓

    Least privilege

    Why this is correct

    Least privilege is a fundamental security principle: subjects receive only the minimum access needed for their tasks. This satisfies the stem's requirement to select genuine fundamental principles, distinguishing it from specific controls or products that merely implement the concept.

  • ✗

    Complexity

    Why it's wrong here

    Complexity is not a fundamental security principle; it actively undermines security by enlarging the attack surface and hiding flaws, whereas the recognised principles are confidentiality, integrity and availability. It is tempting because complex cryptographic algorithms and layered defences genuinely strengthen specific controls, so complexity can be a deliberate design tactic — but never a foundational principle in itself.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.