CompTIA Tech+ (FC0-U71)SecurityMedium
A small business owner wants to ensure that only authorized employees can access specific folders on the company's file server. Each employee should only have access to the files necessary for their job role. Which security principle should the owner implement?
- ADefense in Depth
- BRisk Management
- CLeast Privilege
- DSeparation of Duties
Show answer & explanationAnswer & explanation
Correct answer: C. Least Privilege
The principle of least privilege dictates that users should only be granted the minimum access rights necessary to perform their job functions, preventing unauthorized access to sensitive data.
Why the other options are wrong
- A. Defense in depth uses multiple layers of security controls to protect assets, which is a broader strategy, not a specific access control principle.
- B. Risk management is the process of identifying, assessing, and controlling risks, which is an overarching security process, not a direct access control mechanism.
- D. Separation of duties divides critical tasks among multiple individuals to prevent fraud, which is not about limiting access to files for job roles.
Least Privilege
A security principle that requires that a user or process be given only the minimum level of access or permissions needed to perform their job function or task.
- Minimizes potential damage from errors or attacks
- Reduces the attack surface
- Fundamental to secure system design
Memory trick: Principles guide security, keeping everything tight.