Implicit deny
The default rule that any access not explicitly permitted is refused, so a request that matches no allow rule fails rather than succeeds.
Implicit deny is the rule that whatever is not explicitly allowed is refused. An access control list, a firewall rule base or a cloud permission policy is read for a matching allow rule; if none matches, the request fails, even though no rule says “deny” for that case. Many firewalls show it as a final deny-all line. The idea goes back to Saltzer and Schroeder’s 1975 design principle of fail-safe defaults, which bases access decisions on permission rather than exclusion, and NIST SP 800-53 Rev. 5 applies it to network traffic in SC-7(5), “deny by default, allow by exception”.
Implicit deny is easily confused with an explicit deny, which is a written rule refusing a specific subject or action. In many systems an explicit deny overrides any allow, while implicit deny only catches what nothing else matched. The default also supports least privilege: a forgotten permission leaves a user without access, which is visible and fixable, instead of with access nobody intended.
Exam relevance: questions in this area tend to describe a request that matches no rule and ask what happens. Candidates are expected to answer that it is refused, and to tell the default from an explicit deny rule.