ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard
A system administrator is configuring network access for a new secure segment. The policy states that if a connection attempt does not explicitly match an 'allow' rule, it must be automatically blocked. This ensures that only services and users specifically permitted can establish connections. What access control principle is being applied?
- ALeast Privilege
- BSeparation of Duties
- CImplicit Deny
- DNeed-to-Know
Show answer & explanationAnswer & explanation
Correct answer: C. Implicit Deny
Implicit Deny is a fundamental security principle in access control lists (ACLs) and firewall rules. It states that if a request (e.g., for network access) does not explicitly match an 'allow' rule, it is automatically denied. This 'deny by default' approach ensures that only explicitly permitted actions are allowed, significantly enhancing security.
Why the other options are wrong
- A. Least Privilege grants minimum necessary access but is a broader principle than the specific rule application described.
- B. Separation of Duties divides critical tasks among individuals, unrelated to network access rules.
- D. Need-to-Know relates to limiting information access based on job function, not network connection rules.
Implicit Deny
A security principle in access control where if a request (e.g., for access) does not explicitly match an 'allow' rule, it is automatically denied by default.
- Also known as 'deny by default'
- Fundamental for firewall and ACL configurations
- Ensures only explicitly permitted actions are allowed
Memory trick: Implicit Deny: 'If it's not explicitly green, it's red!'