Courseiva

CISSP Security Architecture and Engineering Practice Question

A security architect is designing a trusted recovery capability for a high-assurance system that must continue operating during a failure without violating its security policy. The system must be able to recover from a failure while maintaining the security of the data it processes, and must not enter an insecure state during recovery. Which two recovery strategies best satisfy the requirement to maintain security during failure and recovery? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any recovery method that restores availability is acceptable, when the requirement is specifically to maintain security during failure and recovery, which fail-soft and fail-secure achieve but fail-open does not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fail-secure operation, where the system denies access to resources and defaults to a secure state when a failure is detected.

Fail-soft and fail-secure operations are the two recovery strategies that maintain security during failure. Fail-soft keeps the system running in a degraded but secure mode, isolating the failed component, while fail-secure defaults to denying access and protecting data. Both prevent the system from entering an insecure state, which is essential for trusted recovery in high-assurance systems. Fail-open, cold restart, and manual intervention either compromise security or fail to guarantee continuous protection during recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fail-secure operation, where the system denies access to resources and defaults to a secure state when a failure is detected.

    Why this is correct

    Fail-secure operation ensures that when a failure occurs, the system defaults to a state that denies access and protects data, rather than allowing unsafe access. This maintains the security policy during recovery by refusing to grant access until the system is restored. It prevents an insecure state, which is exactly what the requirement demands, and is a core principle in trusted recovery design for high-assurance systems.

  • ✗

    Fail-open operation, where the system allows all access to maintain availability during a failure.

    Why it's wrong here

    Fail-open operation allows all access when a failure occurs, which directly violates the security policy by permitting unauthorized access. In a high-assurance system that must maintain security during recovery, fail-open would expose data and create an insecure state. Availability is preserved, but at the cost of confidentiality and integrity, making it unsuitable for this scenario where security must not be compromised during failure or recovery.

  • ✗

    Cold restart, where the system reboots and reloads all software from scratch after a failure.

    Why it's wrong here

    A cold restart may restore the system to a known state, but it does not inherently maintain security during the failure or recovery process. There is a window where the system is down or initializing, and if the restart is not carefully controlled, it could load untrusted code or lose security context. It does not guarantee that the system avoids an insecure state during recovery, which is the key requirement here.

  • ✓

    Fail-soft operation, where the system continues to provide degraded but secure functionality while the failed component is isolated.

    Why this is correct

    Fail-soft operation allows the system to continue functioning in a degraded but secure state when a component fails. By isolating the failed component and maintaining security controls on the remaining operations, the system avoids entering an insecure state. This directly satisfies the requirement to recover from failure while preserving security, because the system never fully drops its protections nor exposes data to unauthorized access during the degraded period.

  • ✗

    Manual intervention, where an administrator restores the system from backups after a failure.

    Why it's wrong here

    Manual intervention relies on human action and does not provide automated, immediate secure recovery. During the time before the administrator restores the system, the system may be in an insecure state or unavailable. This approach does not ensure that the system maintains security during failure and recovery without entering an insecure state, and it introduces delay and potential for human error, failing the requirement.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.