CompTIA Tech+ (FC0-U71)SecurityMedium
A system administrator is configuring access controls for a shared network folder. The finance department needs full read, write, and modify permissions, while the marketing department only needs read-only access to specific subfolders. All other employees should have no access. Which of the following best describes the security principle being applied?
- ADefense in depth
- BJob rotation
- CSeparation of duties
- DLeast privilege
Show answer & explanationAnswer & explanation
Correct answer: D. Least privilege
The principle of least privilege dictates that users and systems should only be granted the minimum necessary permissions to perform their authorized tasks. By giving finance full access and marketing read-only, and denying others, the administrator is applying this principle.
Why the other options are wrong
- A. Defense in depth involves multiple layers of security, not granular access permissions.
- B. Job rotation involves moving employees between different roles to reduce the risk of fraud and increase knowledge sharing.
- C. Separation of duties divides critical tasks among multiple individuals to prevent a single point of failure or fraud.
Least Privilege
A security principle that requires giving a user, program, or process only the minimum necessary rights, permissions, or access needed to perform its function.
- Reduces the attack surface and potential damage from compromise.
- Applies to users, applications, and systems.
- A fundamental concept in access control.
Memory trick: Least Privilege: Only the keys you need for your job.