CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a system for a large e-commerce platform that must handle millions of transactions daily. The system needs to be highly resilient and able to tolerate failures of individual components or even entire data centers without significant impact on service availability or data loss. Which general design principle is MOST important to achieve this goal?

  1. APrinciple of Least Privilege.
  2. BSecurity by Obscurity.
  3. CSingle Point of Failure (SPOF) elimination.
  4. DCentralized Logging.
Show answer & explanation

Correct answer: C. Single Point of Failure (SPOF) elimination.

Eliminating Single Points of Failure (SPOF) is the most critical design principle for achieving high resilience and fault tolerance. By ensuring that no single component's failure can bring down the entire system, the platform can continue operating even with component or data center outages.

Why the other options are wrong

  • A. Principle of Least Privilege is a security control that limits access rights but doesn't inherently make the system more resilient to component failures.
  • B. Security by Obscurity is a flawed security practice and does not contribute to resilience or fault tolerance.
  • D. Centralized Logging is crucial for monitoring and incident response but does not directly contribute to the system's ability to tolerate failures.

Single Point of Failure (SPOF) Elimination

Single Point of Failure (SPOF) elimination is a design principle focused on identifying and removing any single component or part of a system whose failure would cause the entire system to stop functioning.

  • Achieved through redundancy, replication, and failover mechanisms.
  • Crucial for high availability and fault tolerance.
  • Applies to hardware, software, network, and data.

Memory trick: Don't put all your eggs in one basket; make sure every critical component has a backup.

More Security Architecture questions