Study. uk . com
  1. Home
  2. All questions
  3. Question 351

CompTIA Security+ study material · question 351 of 611

An authorisation layer is deployed with a deny-by-default posture. What happens when a new endpoint is added and no rule is written for it?

  1. It is refused, so the omission fails closed
  2. It inherits the rule of the nearest endpoint
  3. It is accessible to authenticated users
  4. It is accessible only to administrators
Show the answer

Answer: A. It is refused, so the omission fails closed

Deny by default converts a forgotten rule into an outage rather than into an exposure.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Broken Access Control

Challenge yourself on this topic → Study as cards