CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

An organization is migrating its customer relationship management (CRM) database to a new platform. During the migration, a security audit reveals that many database users have excessive privileges, including `DELETE` and `DROP` permissions on critical tables, even if their job function does not require them. What principle of database security is being violated, and what should the database administrator implement to correct this?

  1. APrinciple of least privilege; implement role-based access control (RBAC).
  2. BPrinciple of data minimization; implement data masking for sensitive fields.
  3. CPrinciple of separation of duties; implement database activity monitoring (DAM).
  4. DPrinciple of defense in depth; implement a web application firewall (WAF).
Show answer & explanation

Correct answer: A. Principle of least privilege; implement role-based access control (RBAC).

The scenario describes users having more permissions than necessary for their job functions, which is a direct violation of the principle of least privilege. Implementing Role-Based Access Control (RBAC) allows administrators to define roles with only the necessary permissions and then assign users to those roles, effectively enforcing least privilege.

Why the other options are wrong

  • B. Data minimization reduces the amount of data stored, and data masking obscures it; neither directly fixes excessive user permissions.
  • C. Separation of duties prevents a single person from completing a critical task, while DAM monitors activity; neither solely addresses excessive standing permissions.
  • D. Defense in depth is a strategy, and a WAF protects web apps, neither directly addresses excessive internal database user permissions.

Principle of Least Privilege

The principle of least privilege dictates that users, programs, or processes should be granted only the minimum level of access or permissions necessary to perform their legitimate functions, and no more.

  • Reduces attack surface.
  • Limits damage from compromised accounts.
  • Fundamental security best practice.

Memory trick: Least Privilege means only 'just enough' keys.

More Data and Database Security questions