Which is a primary REST security design principle?
Choose an answer
Tap an option to check your answer.
Correct answer: fail-safe defaults.
Why this is the answer
Fail-safe defaults is a primary REST security design principle because it dictates that access to resources should be denied by default, and only explicitly granted. This minimizes the attack surface by ensuring that if a security mechanism fails, access is not inadvertently granted. Password hashing is a method for securing credentials, not a design principle for REST security itself. Adding a timestamp to requests can help prevent replay attacks but is a specific security control, not a broad design principle. OAuth is an authorization framework, a specific protocol used for delegated authorization, rather than a general security design principle for REST APIs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed