CompTIA Cloud Essentials+ (CLO-002)Management and Technical OperationsMedium
A cloud security engineer is designing an identity and access management (IAM) solution for a multi-cloud environment. They need to ensure that users have the minimum necessary permissions to perform their job functions across different cloud providers, and that these permissions are revoked automatically when a user's role changes or they leave the organization. Which IAM principle is being emphasized here?
- AShared Responsibility Model
- BLeast Privilege
- CDefense in Depth
- DSecurity by Obscurity
Show answer & explanationAnswer & explanation
Correct answer: B. Least Privilege
The principle of Least Privilege dictates that users, programs, or processes should be granted only the minimum access necessary to perform their legitimate functions, and no more. This minimizes the risk of unauthorized actions or data breaches.
Why the other options are wrong
- A. Shared Responsibility Model defines who is responsible for what in cloud security, not a principle for user permissions.
- C. Defense in Depth involves multiple layers of security controls, not specifically about user permissions.
- D. Security by Obscurity relies on hiding information, which is not a recommended security principle and is unrelated to user permissions.
Principle of Least Privilege
A security best practice requiring that users, programs, or processes be granted only the essential permissions needed to perform their assigned task.
- Minimizes the attack surface and potential damage from compromise.
- Applies to human users and automated processes.
- Requires regular review and adjustment of permissions.
Memory trick: Give only the least key, then take it away.