CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard
A server administrator is reviewing the access controls for a critical production database server. The current configuration grants all database administrators full 'root' equivalent access to the underlying operating system. To align with security best practices and minimize potential harm from accidental errors or malicious activity, which principle should the administrator enforce?
- ASeparation of Duties
- BNeed-to-Know
- CPrinciple of Least Privilege (PoLP)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Principle of Least Privilege (PoLP)
The Principle of Least Privilege (PoLP) dictates that users, programs, and processes should be granted only the minimum necessary permissions to perform their specific tasks. Granting 'root' equivalent access to all database administrators violates this principle and increases risk.
Why the other options are wrong
- A. Separation of Duties ensures that no single individual can complete a critical task alone, but it doesn't directly address the scope of privileges for a given role.
- B. Need-to-Know is related to data access, ensuring users only access data relevant to their work, but PoLP is broader, covering all types of permissions.
- D. Role-Based Access Control (RBAC) is a method for implementing access control, but PoLP is the underlying principle that should guide the definition of those roles and their permissions.
Principle of Least Privilege (PoLP)
A security concept that states a user, program, or process should be given only the minimum levels of access necessary to complete its tasks.
- Reduces attack surface and impact of compromise.
- Applies to users, applications, and services.
- Requires careful definition of roles and permissions.
Memory trick: Access: only what you 'need', no more.