ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy
A security architect is designing a new system that needs to operate reliably even when individual components fail. The system processes critical data, and any interruption in service could have severe consequences. Which architectural principle should be heavily incorporated to ensure continuous operation and data availability?
- ASeparation of Duties
- BSecurity by Obscurity
- CPrinciple of Least Privilege
- DFault Tolerance
Show answer & explanationAnswer & explanation
Correct answer: D. Fault Tolerance
Fault tolerance is an architectural principle that ensures a system can continue to operate without interruption, often at a reduced level, when one or more of its components fail. This is critical for systems where continuous operation and data availability are paramount.
Why the other options are wrong
- A. Separation of Duties is a control mechanism to prevent fraud or error, not system availability during failures.
- B. Security by Obscurity is generally considered a weak security principle and doesn't address system reliability.
- C. Least Privilege is about access control, not system resilience to failures.
Fault Tolerance
The ability of a system to continue performing its intended function without interruption in the event of a component failure.
- Achieved through redundancy (e.g., redundant power supplies, servers, network paths).
- Ensures high availability and business continuity.
- Often involves automatic failover mechanisms.
Memory trick: Fault tolerance: when one part fails, the system doesn't.