easyMultiple Select
CISSP Practice Question: Which THREE are core principles of secure system…
Which THREE are core principles of secure system design?
⚠ Common exam trap
ISC2 often tests the distinction between 'security through obscurity' as a valid supplementary measure versus a core principle, and candidates mistakenly select it because they confuse obfuscation with a foundational design tenet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Least privilege (C) is a core secure design principle because each user, process, or service should be granted only the minimum access rights and permissions required to perform its function, limiting the blast radius of a compromise. Fail securely (D) is correct because systems should default to a safe, denying state when errors, exceptions, or failures occur, so that a failure does not inadvertently expose data or bypass controls. Defense in depth (E) is correct because relying on multiple, layered, and independent security controls ensures that if one control fails, others still protect the asset. Complexity (A) is not a security principle; unnecessary complexity actually increases the attack surface and the likelihood of misconfiguration and vulnerabilities. Security through obscurity (B) is not a core principle because hiding design details or secrets does not provide real protection once the obscurity is bypassed or discovered, and it should never replace proper security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Complexity increases security
Why it's wrong here
Complexity makes systems harder to understand, audit, and secure effectively. More components, intricate interactions, and extensive code paths inherently increase the attack surface and the likelihood of introducing undiscovered vulnerabilities or misconfigurations. Simplicity, conversely, often correlates with better security because it reduces potential error points, facilitates thorough analysis, and makes verification of security properties more manageable.
- ✗
Security through obscurity
Why it's wrong here
Security through obscurity is a flawed principle that attempts to achieve security by hiding the details of a system's design or implementation, rather than by making it fundamentally robust and resilient. This approach is ineffective because once the "secret" (e.g., a hidden port or undocumented API) is discovered, the system's security completely collapses. True security relies on open, peer-reviewed algorithms and strong, verifiable controls that withstand scrutiny, not on secrecy.
- ✓
Least privilege
Why this is correct
The principle of least privilege dictates that every subject (e.g., user, process, or program) should be granted only the minimum set of permissions and access rights necessary to perform its legitimate function and no more. This minimizes the potential damage an attacker can inflict if a system component or account is compromised, restricting lateral movement and limiting data exfiltration. It is a fundamental control for reducing the blast radius of security incidents.
- ✓
Fail securely
Why this is correct
The "fail securely" principle mandates that in the event of a system failure, error, or unexpected condition, the system should transition into a state that is inherently secure rather than insecure. This means defaulting to denial of access, locking down resources, or halting operations in a way that prevents unauthorized disclosure, modification, or destruction of data. For example, a failed authentication system should deny access rather than inadvertently grant it.
- ✓
Defense in depth
Why this is correct
Defense in depth is a cybersecurity strategy that employs multiple, independent layers of security controls to protect assets and information. This approach ensures that if one security control fails or is bypassed, other controls are still in place to prevent or detect an attack, thereby eliminating single points of failure. It encompasses administrative, technical, and physical safeguards, creating a robust and resilient security posture against various threats.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.