CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy

A database administrator is configuring access controls for a new production database. The security policy states that users should only have the minimum necessary privileges to perform their job functions. A new data analyst needs to query specific tables for reporting but should not be able to modify or delete any data. Which of the following access control principles is primarily being applied here?

  1. ANeed-to-Know
  2. BSeparation of Duties
  3. CLeast Privilege
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: C. Least Privilege

The principle of least privilege dictates that users should be granted only the essential permissions required to perform their assigned tasks, and no more. Restricting the data analyst to query-only access exemplifies this.

Why the other options are wrong

  • A. Need-to-Know is an access control principle where users are granted access to information only if they require it to perform their duties; while related, 'least privilege' is a more direct fit for defining the *level* of access.
  • B. Separation of Duties involves dividing critical tasks among multiple individuals to prevent fraud or error, which is not the primary focus here.
  • D. RBAC is a *method* of implementing access control, where permissions are assigned to roles, and users are assigned to roles. While RBAC might be used to implement least privilege, the question asks for the *principle* being applied.

Least Privilege

A security principle where users and systems are granted only the minimum necessary permissions to perform their authorized functions.

  • Limits the potential damage from accidental errors or malicious actions.
  • Reduces the attack surface.
  • Applies to users, processes, and applications.

Memory trick: Principles are like rules for who gets the key to which door.

More Data and Database Security questions