nerdexam
(ISC)2

CISSP · Question #1174

Information security practitioners are in the midst of implementing a new firewall. Which of the following failure methods would BEST prioritize security in the event of failure?

The correct answer is A. Fail-Closed. The failure method that would best prioritize security in the event of failure is fail-closed. Fail- closed is a failure mode that blocks or denies all access when a system or a component fails or malfunctions. Fail-closed is also known as fail-secure or fail-safe, as it…

Submitted by zhang_li· Mar 5, 2026Communication and Network Security

Question

Information security practitioners are in the midst of implementing a new firewall. Which of the following failure methods would BEST prioritize security in the event of failure?

Options

  • AFail-Closed
  • BFail-Open
  • CFail-Safe
  • DFailover

How the community answered

(40 responses)
  • A
    93% (37)
  • C
    3% (1)
  • D
    5% (2)

Explanation

The failure method that would best prioritize security in the event of failure is fail-closed. Fail- closed is a failure mode that blocks or denies all access when a system or a component fails or malfunctions. Fail-closed is also known as fail-secure or fail-safe, as it prevents unauthorized or malicious access and preserves the confidentiality and integrity of the system or the data. Fail- closed is suitable for systems or components that handle sensitive or critical information or operations, and where security is more important than availability. Fail-open is a failure mode that allows or grants all access when a system or a component fails or malfunctions. Fail-open is also known as fail-insecure or fail-soft, as it enables authorized or legitimate access and preserves the availability and functionality of the system or the data. Fail-open is suitable for systems or components that handle non-sensitive or non-critical information or operations, and where availability is more important than security. Failover is a failure mode that switches or transfers the access to a backup or redundant system or component when the primary system or component fails or malfunctions. Failover is also known as fault tolerance or high availability, as it maintains the continuity and reliability of the system or the data. Failover is suitable for systems or components that handle vital or essential information or operations, and where both security and availability are equally important.

Topics

#fail-closed#firewall security#network resilience

Community Discussion

No community discussion yet for this question.

Full CISSP Practice