ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A system administrator is configuring firewall rules for a new secure network segment. The security policy dictates that only explicitly permitted traffic should be allowed, and all other traffic must be blocked by default. Which access control principle is being applied here?

  1. ALeast Privilege
  2. BSeparation of Duties
  3. CImplicit Deny
  4. DNeed-to-Know
Show answer & explanation

Correct answer: C. Implicit Deny

Implicit Deny is a fundamental security principle stating that if a specific access rule (e.g., for traffic, files, or services) is not explicitly permitted, then it is automatically denied. This directly matches the scenario of blocking all traffic by default unless explicitly allowed.

Why the other options are wrong

  • A. Least Privilege grants minimum necessary permissions, but 'Implicit Deny' describes the default action for unpermitted actions.
  • B. Separation of Duties divides critical tasks, unrelated to firewall default actions.
  • D. Need-to-Know applies to information access based on job function, not a default firewall rule.

Implicit Deny

A fundamental security principle that states if a specific access request is not explicitly permitted, then it should be denied by default.

  • A 'fail-safe' or 'default-deny' approach.
  • Reduces the attack surface by blocking unknown or unauthorized access.
  • Commonly applied in firewalls, access control lists (ACLs), and application permissions.

Memory trick: Implicit Deny means if it's not on the 'allow' list, it's automatically DENIED.

More Access Controls Concepts questions