AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy
A cloud administrator is designing IAM policies for a new team and wants to ensure each user can perform only the actions required for their specific job function. Which security principle does this describe?
- ASeparation of duties
- BPrinciple of least privilege
- CShared responsibility model
- DDefense in depth
Show answer & explanationAnswer & explanation
Correct answer: B. Principle of least privilege
The principle of least privilege means granting only the minimum permissions necessary for a user or system to perform its function, reducing the attack surface and risk of accidental or malicious misuse.
Why the other options are wrong
- A. Separation of duties splits tasks among multiple people to prevent fraud, a related but different concept.
- C. Shared responsibility model defines security duties between AWS and the customer, not user permissions.
- D. Defense in depth refers to layered security controls, not permission scoping.
Principle of Least Privilege
A security best practice of granting users or systems only the permissions necessary to perform their required tasks.
- Reduces attack surface
- Applied via scoped IAM policies
- Core AWS Well-Architected security pillar concept
Memory trick: Give only the keys needed, not the whole keyring.