CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityEasy
A cloud administrator reviews user permissions and revokes any access rights that exceed what each employee needs to perform their specific job duties, ensuring every account has only the minimum access required. Which security principle is being applied?
- ALeast privilege
- BSeparation of duties
- CDefault allow
- DMandatory access control
Show answer & explanationAnswer & explanation
Correct answer: A. Least privilege
The principle of least privilege states that users should be granted only the minimum access rights necessary to perform their job functions, reducing the attack surface and potential for misuse. Separation of duties splits critical tasks among multiple people, mandatory access control enforces labels set by a central authority, and default allow is an insecure posture granting access unless explicitly denied.
Why the other options are wrong
- B. Separation of duties divides responsibilities among multiple people, not about minimizing individual access levels.
- C. Default allow is the opposite of a secure posture and is not what's described here.
- D. Mandatory access control is a specific access model using security labels, not simply minimizing rights.
Least Privilege
A security principle stating that users, accounts, and processes should be granted only the minimum level of access necessary to perform their required functions.
- Reduces attack surface and potential damage from compromised accounts
- Applies to users, applications, and system processes alike
- Often implemented alongside RBAC and periodic access reviews
Memory trick: Give each key only to the doors that person actually needs to open.