How Should Safety and Logical Controls Be Configured During System Failures?

Security Architecture & Physical Safety

Security controls in a data center are being reviewed to ensure data is properly protected and that human life considerations are included. Which of the following best describes how the controls should be set up?

  1. Remote access points should fail closed.
  2. Logging controls should fail open.
  3. Safety controls should fail open. Source Reference Answer
  4. Logical security controls should fail closed.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Assesses the fail-safe/fail-open dichotomy, where the common trap involves applying data-centric fail-closed logic to physical safety scenarios that explicitly require fail-open behavior.

This question evaluates the fail-safe versus fail-open design principles in security architecture, with community consensus confirming that safety mechanisms must prioritize human life by defaulting to an open state during failures.

Candidates often select Option D because logical security controls do indeed fail closed, but they miss the question’s explicit directive to prioritize human life considerations, which overrides standard data protection defaults.

Community Discussion (7 comments)

dbrowndiver 👍 6 Selected: C
Safety controls failing open is a critical design principle that ensures human life is prioritized in the event of a failure. This principle applies to situations where failing open provides an immediate safety benefit, such as allowing exit doors to unlock automatically during a fire.
MarysSon 👍 2 Selected: C
The question says human life considerations are included. Human life is the main concern. C is the only answer that adequately addresses the safety of the workforce.
41c27e6 👍 1 Selected: D
Logical security controls. If there is a failure in the security system (such as a logical security control), the system should default to a more secure state, blocking any unauthorized access
Cristian_Ykz 👍 1 Selected: D
I think the key to the answer lies in "Logical Security Controls" Logical security controls (such as firewalls, ACLs, authentication, etc.) must fail-safe (close) upon failure to ensure that the system remains secure and unauthorized access is blocked. This helps proactively protect critical data and resources, reducing exposure to risk. If there were no specification of the control applied, this would not be a good option.
Shaman73 👍 1 Selected: C
C. Safety controls should fail open.
Yoez 👍 4 Selected: C
C. Safety controls should fail open: Safety controls, such as fire suppression systems or emergency exits, should indeed fail open. This means that in the event of a failure or malfunction, they should default to a state that ensures safety, such as allowing people to exit a building or mitigating hazards.
Mehsotopes 👍 3 Selected: C
Fail Open: Activates specified controls; in this case, safety measures such as sprinklers, or alarm systems to ensure the safety of staff members, & system devices. Fail Close: Locks controls such as access to the perimeter, & devices to protect from exfiltration.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Safety controls in any facility, including data centers, must be designed to fail open to prioritize human life above all else. In the event of a power loss, system malfunction, or emergency, mechanisms like fire suppression releases, electromagnetic door unlocks, and ventilation shut-offs must activate or open automatically. This fail-open configuration ensures that personnel can evacuate safely and that hazards are mitigated immediately, aligning with occupational safety standards and risk management frameworks.

Why the Other Options Are Wrong

Option A is incorrect because remote access points and network boundaries should fail closed to prevent unauthorized lateral movement during outages. Option B misapplies the concept; logging controls are informational and do not operate on a fail-open/closed spectrum, as their primary goal is audit trail continuity rather than access control. Option D describes a valid principle for logical security controls like firewalls and ACLs, but it contradicts the question’s specific emphasis on human life and physical safety, making it the secondary consideration rather than the best overall answer.

Community Comment Notes

The community heavily emphasizes that human life takes precedence over data protection in exam scenarios involving safety priorities [1]. Several users note that while logical controls correctly fail closed, the prompt’s phrasing directly targets physical safety protocols, confirming Option C as the intended answer [4]. Additional feedback clarifies that fail-open activates emergency measures like sprinklers and alarms, whereas fail-close secures perimeters against threats [3]. This consensus reinforces the need to read for contextual cues like human life considerations before selecting technical defaults.

Official Reference

Exam Strategy

Always prioritize keywords like human life, safety, or emergency over standard data-protection rules when configuring controls. Remember that logical and access controls must fail closed to protect assets, while physical safety systems must fail open to preserve lives, a distinction frequently tested across Security+ domains.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide