CompTIA A+ Core 2 (220-1202)SecurityEasy

A technician is setting up a new Windows workstation for a user who will primarily be performing data entry and accessing approved web applications. The company's security policy dictates that users should only have the minimum necessary access rights to perform their job functions. Which of the following security principles is being applied?

  1. ADefense in Depth
  2. BImplicit Deny
  3. CLeast Privilege
  4. DSeparation of Duties
Show answer & explanation

Correct answer: C. Least Privilege

The principle of least privilege ensures users are granted only the essential permissions needed to perform their tasks, reducing potential damage from accidental misuse or malicious activity. Granting minimum necessary access aligns directly with this principle.

Why the other options are wrong

  • A. Defense in depth involves using multiple layers of security controls to protect resources.
  • B. Implicit deny states that if a permission is not explicitly granted, it is denied by default.
  • D. Separation of duties involves dividing critical tasks among multiple individuals to prevent fraud or error.

Least Privilege

A security principle where users, programs, or processes are granted only the minimum access necessary to perform their required functions.

  • Reduces the attack surface.
  • Limits the potential damage from compromised accounts.
  • Requires careful planning of user roles and permissions.

Memory trick: Granting only what's needed keeps things tight and secure.

More Security questions