CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

An organization is preparing for an annual security audit. The auditor requests evidence of adherence to the principle of least privilege for critical systems. Which of the following metrics would be MOST effective in demonstrating compliance with this principle?

  1. ANumber of failed login attempts per day.
  2. BMean Time To Patch (MTTP) critical vulnerabilities.
  3. CPercentage of users with administrative privileges on critical systems.
  4. DTotal volume of network traffic to critical systems.
Show answer & explanation

Correct answer: C. Percentage of users with administrative privileges on critical systems.

The principle of least privilege dictates that users should only have the minimum necessary access to perform their job functions. Therefore, the percentage of users with administrative privileges on critical systems directly measures adherence to this principle.

Why the other options are wrong

  • A. Failed login attempts indicate potential brute-force attacks or misconfigurations, not adherence to least privilege.
  • B. MTTP measures vulnerability remediation efficiency, not access control principles.
  • D. Network traffic volume indicates system usage, not the privilege levels of users accessing those systems.

Least Privilege Metric

A quantitative measure used to assess the extent to which user and system accounts are granted only the minimum necessary permissions to perform their authorized functions.

  • Reduces the attack surface.
  • Limits potential damage from compromised accounts.
  • Often tracked by auditing administrative access levels.

Memory trick: Least privilege: count who has MORE, not who's trying to get in.

More Reporting and Communication questions