Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 33

ThorTeaches.com has recently experienced a data breach due to a malware attack that was able to bypass your current security measures. As the IT security manager, you need to implement additional security measures to prevent similar attacks in the future. Which of the following is the most accurate description of a default deny policy?
  • A A default deny policy denies access to all resources unless explicitly allowed.
  • B A default deny policy allows access to all resources unless explicitly denied by the system administrator.
  • C A default deny policy denies access to all resources unless explicitly allowed by the system administrator.
  • D A default deny policy allows access to all resources unless explicitly prohibited.
Reveal correct answer

Correct answer: A

Explanation

The correct answer: A default deny policy denies access to all resources unless explicitly allowed: A default deny policy is a network security approach where all traffic, whether internal or external, is blocked by default and only explicitly permitted traffic is allowed. This approach is often considered the safest, as it begins from a standpoint of maximum security and only lowers these safeguards when necessary and safe. It reduces the likelihood of unauthorized or malicious access, as permissions have to be intentionally and explicitly given for access to be granted. The incorrect answers: A default deny policy allows access to all resources unless explicitly prohibited: This is incorrect because it describes a 'default allow' policy, not a 'default deny' policy. In a default allow policy, all traffic is allowed by default, unless explicitly blocked. This is a more risky approach, as it potentially allows unauthorized or malicious traffic to access resources, unless these sources are explicitly recognized and blocked. A default deny policy allows access to all resources unless explicitly denied by the system administrator: This answer is also incorrect for the same reason as the first incorrect option. It describes a 'default allow' policy where the system administrator explicitly denies access to certain resources. This approach can be risky as it could allow unauthorized or malicious traffic access to resources. A default deny policy denies access to all resources unless explicitly allowed by the system administrator: This answer is technically correct, but the wording is misleading. While a default deny policy does indeed operate by denying access unless explicitly allowed, the key decision maker in this process is the policy itself, not the system administrator. The system administrator may implement and manage the policy, but the policy operates according to its own rules and parameters. In other words, it's not the administrator's explicit permission that allows access, but rather the policy that the administrator has put in place. This may seem like a minor distinction, but it's important for understanding how these policies work.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need