Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 380 discussion

Actual exam question from ISC's CISSP
Question #: 380
Topic #: 1
[All CISSP Questions]

What security principle addresses the issue of "Security by Obscurity"?

  • A. Open design
  • B. Role Based Access Control (RBAC)
  • C. Segregation of duties (SoD)
  • D. Least privilege
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Loveguitar
Highly Voted 2 years, 2 months ago
Should be open design.
upvoted 9 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
gjimenezf
Most Recent 9 months, 4 weeks ago
Selected Answer: A
Address the issue= solving the issue
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
The security principle that addresses the issue of "Security by Obscurity" is A. Open design. Security through obscurity, or security by obscurity, relies on secrecy as the main method of providing security to a system or component. This approach is discouraged and not recommended by standards bodies, such as the National Institute of Standards and Technology (NIST) in the United States, which recommends against this practice. Instead, the principle of open design emphasizes the importance of designing systems with transparency and openness, rather than relying on secrecy as the primary means of security.
upvoted 1 times
...
lxm28
1 year, 5 months ago
Selected Answer: A
Fuzzy security is the practice of relying on the confidentiality or complexity of a system or algorithm to provide security, rather than on the strength of the system itself. Open design is a security principle that advocates the use of open and transparent designs and protocols that can be scrutinized and tested by the security community to identify and address potential vulnerabilities. This approach is considered more secure than relying on secrecy or concealment to protect the system.
upvoted 1 times
...
lj22hawaii
1 year, 5 months ago
Selected Answer: C The open design security principle states that the implementation details of the design should be independent of the design itself, which can remain open, unlike in the case of security by obscurity wherein the security of the software is dependent upon the obscuring of the design itself. https://github.com/OWASP/DevGuide/blob/master/02-Design/01-Principles%20of%20Security%20Engineering.md
upvoted 1 times
...
Ivanchun
1 year, 7 months ago
Selected Answer: C
ADDRESSES the issue of Security by Obscurity - SoD
upvoted 1 times
...
Delab202
1 year, 7 months ago
Selected Answer: A
Security through Transparency," on the other hand, is the principle of designing security systems that are open and transparent. This approach assumes that if the attacker knows how a system is secured, they will not be able to exploit any vulnerabilities because the system is designed with strong security mechanisms.
upvoted 1 times
...
crazywai1221
1 year, 8 months ago
Selected Answer: A
The security principle that addresses the issue of "Security by Obscurity" is Open Design. Option A is the correct answer. "Security by Obscurity" is a security practice in which security mechanisms are based on the secrecy or complexity of the design rather than on a known and tested security model. This approach is often ineffective because it relies on the assumption that attackers will not be able to discover the security measures or exploit vulnerabilities in the system. The security principle of Open Design addresses this issue by advocating for systems to be designed with security mechanisms that are transparent, well-defined, and publicly known. This approach ensures that security mechanisms are based on sound security principles, can be tested and evaluated, and can be improved over time. By making security mechanisms transparent and publicly known, the risks associated with "Security by Obscurity" can be reduced. Role-Based Access Control (RBAC), Segregation of duties (SoD), and Least privilege are other important security principles, but they do not directly address the issue of "Security by Obscurity."
upvoted 2 times
...
JAckThePip
2 years, 1 month ago
Selected Answer: A
Answer is A https://www.cprime.com/resources/blog/security-by-design-7-principles-you-need-to-know/
upvoted 3 times
...
kptest12
2 years, 1 month ago
Open design should be the answer. Open design will help check more flaws by multiple folks , there by making the product strong
upvoted 2 times
...
jaysparky
2 years, 1 month ago
Answer is A. Security Through Obscurity is the opposite of the Open Design Principle, which states that the security if a mechanism should not depend on the secrecy of its design or implementation.
upvoted 2 times
...
stickerbush1970
2 years, 1 month ago
Selected Answer: A
Agree with A
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...