Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard
During a security audit, it is discovered that several employees have administrative access to systems far beyond what is required for their job functions. For instance, a marketing specialist can modify server configurations, and a junior accountant can access the human resources database. Which fundamental security principle is being violated in this situation?
- AImplicit Deny
- BNeed to Know
- CSeparation of Duties
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: D. Least Privilege
The scenario describes users having more access than necessary to perform their job, which is a direct violation of the Principle of Least Privilege. This principle dictates that users should only be granted the minimum permissions required for their tasks.
Why the other options are wrong
- A. Implicit Deny means that unless explicitly allowed, access is denied. While a good practice, the problem here is explicit excessive grants, not the default deny rule.
- B. Need to Know is a concept within Least Privilege, ensuring access only to information necessary for a task, but Least Privilege is the broader principle being violated here regarding system access.
- C. Separation of Duties prevents a single individual from completing a critical task end-to-end, typically involving multiple steps. While related to access, it's not the primary violation of having excessive permissions for a single role.
Principle of Least Privilege
A security concept that dictates that a user, program, or process should be given only the minimum necessary rights, privileges, or permissions to perform its job or function, and no more. This limits the potential damage from a compromise.
- Reduces the attack surface and potential impact of a breach.
- Applies to users, applications, and services.
- Often implemented through Role-Based Access Control (RBAC).
Memory trick: Access control: Least Privilege means only what you need, Separation of Duties means no one person does it all.