CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium

A security auditor is reviewing the access controls for a critical production server. The auditor discovers that several administrators have been granted 'Full Control' permissions to a shared directory that only needs read access for their daily tasks. This violates which security principle?

  1. ANeed to know
  2. BDefense in depth
  3. CLeast privilege
  4. DSeparation of duties
Show answer & explanation

Correct answer: C. Least privilege

The principle of least privilege dictates that users and processes should only be granted the minimum necessary permissions to perform their authorized functions. Granting 'Full Control' when only 'Read' is needed directly violates this principle.

Why the other options are wrong

  • A. Need to know is a concept where access is granted only when an individual requires it to perform their job, which is related but 'least privilege' is more precise for the *level* of access.
  • B. Defense in depth involves using multiple layers of security controls, which is a broader concept not specifically violated by this access issue.
  • D. Separation of duties involves dividing critical tasks among multiple individuals to prevent fraud or error, which is not directly addressed here.

Principle of Least Privilege (PoLP)

A security principle that requires users, programs, and processes to be granted only the minimum necessary permissions to perform their authorized functions.

  • Minimizes potential damage from errors or malicious acts.
  • Reduces the attack surface.
  • A fundamental concept in access control.

Memory trick: Only give what's needed, no more, no less.

More Security and Disaster Recovery questions