CompTIA A+ Core 2 (220-1202)SecurityEasy
A technician is setting up a new Windows workstation for a user who will primarily be performing data entry tasks and accessing shared network folders. The company policy dictates that users should only have the minimum necessary permissions to perform their job functions. Which principle should the technician apply when configuring the user's access rights?
- ALeast Privilege
- BDefense in Depth
- CImplicit Deny
- DSeparation of Duties
Show answer & explanationAnswer & explanation
Correct answer: A. Least Privilege
The principle of least privilege ensures that users are granted only the essential permissions required to perform their job duties, minimizing potential security risks. This prevents accidental or malicious actions from causing widespread damage.
Why the other options are wrong
- B. Defense in Depth involves multiple layers of security controls, which is a broader strategy, not a specific access rights principle.
- C. Implicit Deny means that unless explicitly allowed, access is denied, which is a mechanism to enforce least privilege, not the principle itself.
- D. Separation of Duties prevents a single individual from controlling an entire critical process, which is not the focus here.
Least Privilege
A security principle where a user, program, or process is given only the minimum necessary authorization to perform its function.
- Minimizes the potential for damage from errors or malicious acts.
- Reduces the attack surface of a system.
- Often implemented through granular access control lists (ACLs).
Memory trick: Don't give too much, just enough to do the job.