nerdexam
EC-Council

212-89 · Question #15

Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide…

The correct answer is C. Permissive policy. A permissive security policy is characterized by allowing all activities except those that are explicitly blocked. This approach starts with a default state of allowing access and functionality, with restrictions applied only to known dangerous services, attacks, or behaviors…

Incident Handling and Response Planning

Question

Rica works as an incident handler for an international company. As part of her role, she must review the present security policy implemented. Upon inspection, Rica finds that the policy is wide open, and only known dangerous services/attacks or behaviors are blocked. Which of the following is the current policy that Rica identified?

Options

  • APrudent policy
  • BParanoic policy
  • CPermissive policy
  • DPromiscuous policy

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    85% (22)
  • D
    12% (3)

Explanation

A permissive security policy is characterized by allowing all activities except those that are explicitly blocked. This approach starts with a default state of allowing access and functionality, with restrictions applied only to known dangerous services, attacks, or behaviors. Such a policy can lead to a wider attack surface because it assumes services and behaviors are safe unless proven otherwise. A prudent policy would typically involve more conservative security measures, applying necessary restrictions to protect against identified and potential threats. A paranoic policy would be at the extreme end of security measures, possibly blocking more than necessary to ensure the highest level of security, often at the expense of usability or functionality. A promiscuous policy, in contrast, would be even more open than a permissive policy, essentially allowing nearly all traffic or actions with minimal restrictions, which is not what Rica observed.

Topics

#security policy types#permissive policy#firewall policy#policy identification

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice