CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy

A database administrator is configuring a new production database that stores customer account information. To comply with internal security policies and industry best practices, the administrator needs to ensure that users only have the minimum necessary permissions to perform their job functions. Which security principle is the administrator applying?

  1. ALeast privilege
  2. BDefense in depth
  3. CSeparation of duties
  4. DNeed-to-know
Show answer & explanation

Correct answer: A. Least privilege

The principle of least privilege dictates that users should be granted only the essential permissions required to perform their assigned tasks, minimizing the potential impact of a compromised account.

Why the other options are wrong

  • B. Defense in depth involves multiple layers of security, not just minimal permissions.
  • C. Separation of duties distributes critical tasks among multiple individuals to prevent fraud, distinct from individual user permissions.
  • D. Need-to-know is similar to least privilege but often refers to access to information, while least privilege is broader for system permissions.

Least Privilege

A security principle requiring that users and processes are granted only the minimum necessary permissions to perform their work.

  • Reduces the attack surface and potential damage from compromised accounts.
  • Applies to file system permissions, database roles, and application access.
  • Requires careful analysis of job functions to define appropriate permissions.

Memory trick: Give just enough key, not the whole ring.

More Data and Database Security questions