AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A cloud administrator is designing IAM policies for a new team and wants to ensure each user can perform only the actions required for their specific job function. Which security principle does this describe?

  1. ASeparation of duties
  2. BPrinciple of least privilege
  3. CShared responsibility model
  4. DDefense in depth
Show answer & explanation

Correct answer: B. Principle of least privilege

The principle of least privilege means granting only the minimum permissions necessary for a user or system to perform its function, reducing the attack surface and risk of accidental or malicious misuse.

Why the other options are wrong

  • A. Separation of duties splits tasks among multiple people to prevent fraud, a related but different concept.
  • C. Shared responsibility model defines security duties between AWS and the customer, not user permissions.
  • D. Defense in depth refers to layered security controls, not permission scoping.

Principle of Least Privilege

A security best practice of granting users or systems only the permissions necessary to perform their required tasks.

  • Reduces attack surface
  • Applied via scoped IAM policies
  • Core AWS Well-Architected security pillar concept

Memory trick: Give only the keys needed, not the whole keyring.

More Security and Compliance questions