CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsMedium

A company's IT security policy states that new employees are granted access only to the specific systems and data required to perform their assigned job duties at the time of hire. Any additional access must go through a formal request and approval process. Which access control principle does this policy describe?

  1. ALeast privilege
  2. BSeparation of duties
  3. CRole-based access control
  4. DAttribute-based access control
Show answer & explanation

Correct answer: A. Least privilege

Least privilege is the principle of granting users the minimum level of access necessary to perform their job functions, with additional access requiring justification and approval. This limits the potential damage from compromised or misused accounts.

Why the other options are wrong

  • B. Separation of duties splits critical tasks among multiple people to prevent fraud, not about minimizing access scope.
  • C. RBAC assigns access based on job role, but the scenario emphasizes minimal necessary access, not role mapping.
  • D. ABAC uses multiple attributes (role, location, time) for access decisions, not described here.

Least Privilege

A security principle stating users should be granted only the minimum access rights needed to perform their job functions.

  • Reduces attack surface and insider risk
  • Additional access requires approval
  • Complements RBAC and ABAC as an overarching goal

Memory trick: LSND: Least privilege, Separation of duties, Need-to-know, Deny by Default

More Data Governance, Quality and Controls questions