CompTIA SecurityX (CAS-005)Security ArchitectureEasy
An organization is designing a new critical infrastructure system that must operate continuously, even if major components fail or are compromised. The security architect is considering principles to ensure the system can withstand such events. Which design principle focuses on the system's ability to maintain operations despite failures or attacks, often through redundancy and isolation?
- AResilience
- BSeparation of Duties
- CDefense in Depth
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: A. Resilience
Resilience in security design refers to a system's ability to continue operating, possibly in a degraded but functional state, when faced with failures, attacks, or unexpected conditions. This is often achieved through redundancy, fault tolerance, and isolation.
Why the other options are wrong
- B. Separation of duties prevents a single individual from completing a critical task alone, which is an administrative control for preventing fraud or error, not system operational continuity.
- C. Defense in depth uses multiple layers of security, which is good for protection but doesn't specifically address the system's ability to 'maintain operations' during a failure.
- D. Least privilege limits access rights to only what is necessary, which improves security but doesn't directly ensure continuous operation during failures.
Resilient Architecture
A resilient architecture is designed to withstand and recover from various failures, attacks, or unexpected conditions, maintaining its core functionality and operations even when components are compromised or unavailable.
- Focuses on continuous operation despite disruptions.
- Achieved through redundancy, fault tolerance, isolation, graceful degradation.
- Adapts to changing conditions and recovers quickly.
- Critical for high-availability and critical infrastructure systems.
Memory trick: A strong building can bend but not break.