CompTIA A+ Core 2 (220-1202)SecurityHard
A system administrator is setting up a new Windows workstation for a user who will be handling highly sensitive financial data. The administrator wants to ensure that, even if the user's account is compromised, the attacker cannot delete critical system files or install unauthorized software. Which security principle should be strictly enforced for this user's account?
- ALeast Privilege
- BDefense in Depth
- CImplicit Deny
- DSeparation of Duties
Show answer & explanationAnswer & explanation
Correct answer: A. Least Privilege
The principle of Least Privilege dictates that a user or process should only be granted the minimum necessary permissions to perform its job function. By restricting the user's account to only what is needed for financial data handling, the administrator prevents them (or an attacker compromising their account) from performing actions like deleting system files or installing software.
Why the other options are wrong
- B. Defense in Depth involves multiple layers of security, but Least Privilege is a specific principle applied at the user/system access layer.
- C. Implicit Deny means that unless explicitly allowed, access is denied. While a good principle, it's a mechanism to enforce access control, not the overarching principle of *how much* access to grant.
- D. Separation of Duties divides critical tasks among multiple individuals to prevent fraud, but doesn't directly control the permissions of a single user account in this manner.
Least Privilege
A security principle that requires that a user or process be given only the minimum level of access or permissions needed to perform its authorized functions, and no more. This limits the potential damage if an account or system is compromised.
- Grants minimum necessary permissions
- Reduces attack surface and potential damage
- Applies to users, applications, and services
- A fundamental principle in security design
Memory trick: Least Privilege means giving only a tiny key, not the master key.