- Home
- All questions
- Question 351
CompTIA Security+ study material · question 351 of 611
An authorisation layer is deployed with a deny-by-default posture. What happens when a new endpoint is added and no rule is written for it?
Show the answer
Answer: A. It is refused, so the omission fails closed
Deny by default converts a forgotten rule into an outage rather than into an exposure.
Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Broken Access Control