CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard

A security analyst is reviewing a server's configuration to ensure it adheres to the principle of least privilege. The analyst finds that a critical application service is running with root privileges, even though its operational requirements only involve writing to a specific log file and reading from a configuration directory. What is the most appropriate action to align this service with the principle of least privilege?

  1. AEncrypt the log file and configuration directory.
  2. BDisable the service and run it manually when needed.
  3. CImplement a host-based intrusion detection system (HIDS).
  4. DChange the service's ownership to a non-root user with specific permissions.
Show answer & explanation

Correct answer: D. Change the service's ownership to a non-root user with specific permissions.

The principle of least privilege dictates that a process or user should only have the minimum necessary permissions to perform its function. Running a service as root when it only needs access to a few specific resources violates this. Creating a dedicated non-root user with read/write permissions only for the required log file and read-only for the configuration directory directly implements the principle of least privilege, significantly reducing the impact if the service is compromised.

Why the other options are wrong

  • A. Encrypting files protects data at rest but does not address the issue of the service having excessive runtime privileges.
  • B. Disabling the service and running manually is not a practical solution for a critical application that needs to be continuously available.
  • C. A HIDS monitors for suspicious activity but does not prevent a compromised root service from exploiting its excessive privileges.

Principle of Least Privilege (PoLP)

A security concept in which a user, program, or process is given only the minimum necessary rights, permissions, or access level to perform its function.

  • Reduces the attack surface and potential damage from compromise.
  • Applies to users, applications, and services.
  • Requires careful analysis of actual operational needs.

Memory trick: Security Principles: 'Least Privilege' means less 'power' to exploit!

More Security and Disaster Recovery questions