shieldCISSP Practice Domain 3 — Security Architecture and Engineering Q70 of 120

Which design principle says that complex protection mechanisms should be avoided in favor of simpler ones that are easier to verify?

A CISSP practice question covering Domain 3: Security Architecture and Engineering. Try answering before reading the explanation below.

Show options & answer
A
Defense in depth
B
Economy of mechanism
✓ Correct answer
C
Fail-safe defaults
D
Open design
Why "Economy of mechanism" is the right answer

Economy of mechanism (Saltzer & Schroeder) — simpler designs are easier to assure. Defense in depth layers controls. Fail-safe defaults say deny by default. Open design says don't rely on secret algorithms (Kerckhoffs's principle).

Study videos for this topic

Want to go deeper on Domain 3? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →